mCloud Panel Installer Scanner

Targets the mCloud Panel installation endpoint to detect exposed setup interfaces, enabling attackers to reinstall or modify cloud management configurations.

Short Info


Level

Critical

Single Scan

Single Scan

Can be used by

Asset Owner

Estimated Time

10 seconds

Time Interval

1 month 5 days

Scan only one

URL

Toolbox

mCloud Panel is a cloud management platform used by IT administrators and cloud service providers to oversee infrastructure, provision resources, and automate administrative tasks. It offers a centralized dashboard for monitoring performance, managing costs, and ensuring compliance across multi-cloud environments. Organizations rely on it to streamline operations and maintain control over their cloud assets.

The Installation Page Exposure vulnerability arises when the installation interface of mCloud Panel remains accessible after initial setup. This typically occurs due to improper access controls or failure to remove installation scripts post-deployment. Attackers can exploit this to reinstall the panel, overwrite configurations, or gain administrative access.

Technically, the vulnerability targets the /install or /setup endpoint of mCloud Panel, where installation scripts are left exposed. These scripts often lack authentication, allowing anyone to execute setup procedures. The exposure can be detected by scanning for specific files like install.php or setup.php in the panel's root directory.

If exploited, an attacker could completely reinstall mCloud Panel, gaining full administrative control over cloud resources. This could lead to data breaches, service disruption, and unauthorized provisioning of virtual machines. The high CVSS score of 9.4 reflects the critical risk of total compromise.

Get started to protecting your digital assets