An authentication bypass exists on CyberPower PowerPanel...
Critical severity
Unreviewed
Published
Aug 14, 2023
to the GitHub Advisory Database
•
Updated Apr 4, 2024
Description
Published by the National Vulnerability Database
Aug 14, 2023
Published to the GitHub Advisory Database
Aug 14, 2023
Last updated
Apr 4, 2024
An authentication bypass exists on CyberPower PowerPanel Enterprise by failing to sanitize meta-characters from the username, allowing an attacker to login into the application with the default user "cyberpower" by appending a non-printable character.An unauthenticated attacker can leverage this vulnerability to log in to the CypberPower PowerPanel Enterprise as an administrator with hardcoded default credentials.
References