CVE-2025-34430
Severity CVSS v4.0:
MEDIUM
Type:
CWE-352
Cross-Site Request Forgery (CSRF)
Publication date:
10/12/2025
Last modified:
23/12/2025
Description
1Panel versions 1.10.33 through 2.0.15 contain a cross-site request forgery (CSRF) vulnerability in the panel name management functionality. The affected endpoint does not implement CSRF defenses such as anti-CSRF tokens or Origin/Referer validation. An attacker can craft a malicious webpage that submits a panel-name change request; if a victim visits the page while authenticated, the browser includes valid session cookies and the request succeeds. This allows a remote attacker to change the victim’s panel name to an arbitrary value without consent.
Impact
Base Score 4.0
5.10
Severity 4.0
MEDIUM
Base Score 3.x
4.30
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:fit2cloud:1panel:*:*:*:*:*:*:*:* | 1.10.33-lts (including) | 2.0.15 (including) |
To consult the complete list of CPE names with products and versions, see this page



