S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-35885 Scanner

Detects 'Remote Code Execution (RCE)' vulnerability in CloudPanel affects v. 2 before 2.3.1.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.6k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
2
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-35885
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

CloudPanel is a web hosting control panel that enables users to manage their hosting environment efficiently. It combines various features and tools to help users maintain their website securely and effortlessly. Whether you are running a modest website or a complex web application, CloudPanel has the necessary features to manage your hosting environment with ease.

Recently, cybersecurity researchers discovered a vulnerability in the CloudPanel, known as CVE-2023-35885. This vulnerability relates to an insecure file-manager cookie authentication that potentially exposes users’ data and information to cyber-criminals. This particular vulnerability gives attackers an opportunity to gain unauthorized access to a user's CloudPanel instance by stealing the authentication token through manipulating cookies.

If exploited, an attacker can potentially access sensitive information, compromise legitimate accounts, and perform various malicious activities on a user's hosting environment. This includes manipulating files, stealing data, and even spreading malware. The impact of such activities can be catastrophic for a company's reputation and financial standing.

s4e.io is a platform that provides a range of pro features that can help users easily and quickly learn about vulnerabilities in their digital assets. Subscribing to this platform can help users to stay informed about the latest vulnerabilities that threaten their digital assets and obtain expert advice on how to protect them. s4e.io also provides users with practical steps to take in mitigating vulnerabilities detected in their digital assets.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users can take several precautionary measures. These include:

  • Immediately upgrading to the latest version of CloudPanel which has a fixed version of this vulnerability.
  • Configuring Firewall and Intrusion Prevention System to block attacks aimed at the CloudPanel instance.
  • Reviewing users' accounts on the hosting account and revoking access privileges of any untrusted users.
  • Educating users on safer browsing and email habits.
  • Implementing multi-factor authentication (MFA) to increase account security.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.