No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sun, 17 May 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Midoks
Midoks mdserver-web |
|
| Vendors & Products |
Midoks
Midoks mdserver-web |
Sat, 16 May 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 14 May 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | mdserver-web is a simple Linux panel. From 0.18.0 to 0.18.4, mdserver-web has a front-end unauthorized remote command execution vulnerability. Due to the lack of authentication on the /modify_crond and /start_task interfaces, it is possible to modify the default built-in scheduled tasks and start them, achieving RCE. | |
| Title | mdserver-web: Missing Authorization and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | |
| Weaknesses | CWE-78 CWE-862 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-16T00:45:39.514Z
Reserved: 2026-04-20T14:01:46.671Z
Link: CVE-2026-41315
Updated: 2026-05-16T00:44:46.267Z
Status : Awaiting Analysis
Published: 2026-05-14T19:16:35.127
Modified: 2026-05-16T01:16:16.010
Link: CVE-2026-41315
No data.
OpenCVE Enrichment
Updated: 2026-05-17T17:02:08Z