CVE Explorer
CVE-2025-66507
1Panel is an open-source, web-based control panel for Linux server management. Versions 2.0.13 and below allow an unauthenticated attacker to disable CAPTCHA verification by abusing a client-controlled parameter. Because the server previously trusted this value without proper validation, CAPTCHA protections can be bypassed, enabling automated login attempts and significantly increasing the risk of account takeover (ATO). This issue is fixed in version 2.0.14.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 3 assertions
{"cweId":"CWE-807","description":"CWE-807: Reliance on Untrusted Inputs in a Security Decision","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:fe2a94b4cef6eb84c747dff105f0b2bff05a1774f6cb06d96349dfb0f3d255a8 · sha256:9002a3d4c37e29ab… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-602","description":"CWE-602: Client-Side Enforcement of Server-Side Security","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:fe2a94b4cef6eb84c747dff105f0b2bff05a1774f6cb06d96349dfb0f3d255a8 · sha256:9002a3d4c37e29ab… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-290","description":"CWE-290: Authentication Bypass by Spoofing","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:fe2a94b4cef6eb84c747dff105f0b2bff05a1774f6cb06d96349dfb0f3d255a8 · sha256:9002a3d4c37e29ab… · /containers/cna/problemTypes/2/descriptions/0
Affected products and versions
1 source assertion{"product":"1Panel","vendor":"1Panel-dev","versions":[{"status":"affected","version":"< 2.0.14"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:fe2a94b4cef6eb84c747dff105f0b2bff05a1774f6cb06d96349dfb0f3d255a8 · sha256:9002a3d4c37e29ab… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:fe2a94b4cef6eb84c747dff105f0b2bff05a1774f6cb06d96349dfb0f3d255a8 · sha256:9002a3d4c37e29ab… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
3 source assertions{"cweId":"CWE-807","description":"CWE-807: Reliance on Untrusted Inputs in a Security Decision","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:fe2a94b4cef6eb84c747dff105f0b2bff05a1774f6cb06d96349dfb0f3d255a8 · sha256:9002a3d4c37e29ab… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-602","description":"CWE-602: Client-Side Enforcement of Server-Side Security","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:fe2a94b4cef6eb84c747dff105f0b2bff05a1774f6cb06d96349dfb0f3d255a8 · sha256:9002a3d4c37e29ab… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-290","description":"CWE-290: Authentication Bypass by Spoofing","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:fe2a94b4cef6eb84c747dff105f0b2bff05a1774f6cb06d96349dfb0f3d255a8 · sha256:9002a3d4c37e29ab… · /containers/cna/problemTypes/2/descriptions/0
Source references
3 source assertions{"name":"https://github.com/1Panel-dev/1Panel/commit/ac43f00273be745f8d04b90b6e2b9c1a40ef7bca","tags":["x_refsource_MISC"],"url":"https://github.com/1Panel-dev/1Panel/commit/ac43f00273be745f8d04b90b6e2b9c1a40ef7bca"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:fe2a94b4cef6eb84c747dff105f0b2bff05a1774f6cb06d96349dfb0f3d255a8 · sha256:9002a3d4c37e29ab… · /containers/cna/references/1
{"name":"https://github.com/1Panel-dev/1Panel/releases/tag/v2.0.14","tags":["x_refsource_MISC"],"url":"https://github.com/1Panel-dev/1Panel/releases/tag/v2.0.14"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:fe2a94b4cef6eb84c747dff105f0b2bff05a1774f6cb06d96349dfb0f3d255a8 · sha256:9002a3d4c37e29ab… · /containers/cna/references/2
{"name":"https://github.com/1Panel-dev/1Panel/security/advisories/GHSA-qmg5-v42x-qqhq","tags":["x_refsource_CONFIRM"],"url":"https://github.com/1Panel-dev/1Panel/security/advisories/GHSA-qmg5-v42x-qqhq"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:fe2a94b4cef6eb84c747dff105f0b2bff05a1774f6cb06d96349dfb0f3d255a8 · sha256:9002a3d4c37e29ab… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.