mdserver-web is a simple Linux panel. From 0.18.0 to 0.18.4, mdserver-web has a front-end unauthorized remote command execution vulnerability. Due to the lack of authentication on the /modify_crond and /start_task interfaces, it is possible to modify the default built-in scheduled tasks and start them, achieving RCE.
Metrics
Affected Vendors & Products
References
History
Thu, 14 May 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | mdserver-web is a simple Linux panel. From 0.18.0 to 0.18.4, mdserver-web has a front-end unauthorized remote command execution vulnerability. Due to the lack of authentication on the /modify_crond and /start_task interfaces, it is possible to modify the default built-in scheduled tasks and start them, achieving RCE. | |
| Title | mdserver-web: Missing Authorization and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | |
| Weaknesses | CWE-78 CWE-862 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-14T18:31:09.710Z
Reserved: 2026-04-20T14:01:46.671Z
Link: CVE-2026-41315
No data.
Status : Received
Published: 2026-05-14T19:16:35.127
Modified: 2026-05-14T19:16:35.127
Link: CVE-2026-41315
No data.
OpenCVE Enrichment
Updated: 2026-05-14T21:00:13Z