7.5
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Description
1Panel is an open-source, web-based control panel for Linux server management. Versions 2.0.13 and below allow an unauthenticated attacker to disable CAPTCHA verification by abusing a client-controlled parameter. Because the server previously trusted this value without proper validation, CAPTCHA protections can be bypassed, enabling automated login attempts and significantly increasing the risk of account takeover (ATO). This issue is fixed in version 2.0.14.
Basic Information
ID
CVE-2025-66507
Source
GitHub_M
Published
Dec 9, 2025 at 01:25
Affected Product
Vendor
1Panel-dev
Product
1Panel
Version
< 2.0.14
Affected Versions
1Panel-dev 1Panel < 2.0.14