Description
1Panel versions 1.10.33 through 2.0.15 contain a cross-site request forgery (CSRF) vulnerability in the panel name management functionality. The affected endpoint does not implement CSRF defenses such as anti-CSRF tokens or Origin/Referer validation. An attacker can craft a malicious webpage that submits a panel-name change request; if a victim visits the page while authenticated, the browser includes valid session cookies and the request succeeds. This allows a remote attacker to change the victim’s panel name to an arbitrary value without consent.
INFO
Published Date :
2025-12-10T18:23:14.598Z
Last Modified :
2026-03-05T12:04:21.600Z
Source :
VulnCheck
AFFECTED PRODUCTS
The following products are affected by CVE-2025-34430 vulnerability.
| Vendors | Products |
|---|---|
| 1panel |
|
| Fit2cloud |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-34430.