One-click Remote Code Execution in CyberPanel v2.4.3 via unauthenticated API endpoints.
This exploit chains multiple vulnerabilities in CyberPanel's AI Scanner feature:
- Unauthenticated Database Injection —
/api/ai-scanner/callbackaccepts arbitrary data without authentication - Stored XSS — Malicious payloads are rendered unsanitized in the admin dashboard
- CSRF to RCE — XSS hijacks admin session to create a malicious cron job
- CyberPanel ≤ 2.4.3