Nginx Proxy Manager
cpe:2.3:a:nginxproxymanager:nginx_proxy_manager:*:*:*:*:*:*:*
- >= 2.9.14, <= 2.15.1
A remote code execution vulnerability has been identified in Nginx Proxy Manager versions 2.9.14 prior to 2.15.1. This vulnerability arises from improper handling of user-supplied data in the setupCertbotPlugins() function of backend/setup.js. Attackers with the 'certificates:manage' permission can exploit this issue by injecting malicious commands into the 'dns_provider_credentials' field. The injected commands are executed without proper sanitization or escaping, leading to arbitrary command execution on the server when the backend is restarted.
Exploitation of this vulnerability allows for authenticated remote code execution on the server where Nginx Proxy Manager is running.
Users can update to Nginx Proxy Manager version 2.15.1 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.