CVE-2025-34410
Last modified
CVE-2025-34410 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. 1Panel versions 1.10.33 - 2.0.15 contain a cross-site request forgery (CSRF) vulnerability in the Change Username functionality available from the settings panel (/settings/panel). The endpoint does not implement CSRF protections such as anti-CSRF tokens or Origin/Referer validation. EPSS estimates a 0.13% chance of exploitation in the next 30 days.
Description
1Panel versions 1.10.33 - 2.0.15 contain a cross-site request forgery (CSRF) vulnerability in the Change Username functionality available from the settings panel (/settings/panel). The endpoint does not implement CSRF protections such as anti-CSRF tokens or Origin/Referer validation. An attacker can craft a malicious webpage that submits a username-change request; when a victim visits the page while authenticated, the browser includes valid session cookies and the request succeeds. This allows an attacker to change the victim’s 1Panel username without consent. After the change, the victim is logged out and unable to log in with the previous username, resulting in account lockout and denial of service.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Fit2cloud | 1panel | >= 1.10.33-lts, <= 2.0.15 |
References
- https://1panel.pro/Product
- https://github.com/1Panel-dev/1Panel/releasesProduct, Release Notes
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-34410?
How severe is CVE-2025-34410?
How do I fix CVE-2025-34410?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-34405Rejected reason: This CVE ID was rejected because it was res…
- CVE-2025-34406MailEnable versions prior to 10.54 contain a reflected cross…6.1
- CVE-2025-34407MailEnable versions prior to 10.54 contain a reflected cross…6.1
- CVE-2025-34408MailEnable versions prior to 10.54 contain a reflected cross…6.1
- CVE-2025-34409MailEnable versions prior to 10.54 contain a reflected cross…6.1
- CVE-2025-3441Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2025-34411Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2025-34412Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2025-34413Legality WHISTLEBLOWING by DigitalPA contains a protection m…7.1
- CVE-2025-34414Entrust Instant Financial Issuance (IFI) On Premise software…9.3
- CVE-2025-34415Rejected reason: This CVE ID was rejected because it was res…
- CVE-2025-34416MailEnable versions prior to 10.54 contain an unsafe DLL loa…7.8
Are you affected by CVE-2025-34410?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
