
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-34410 is a Cross-Site Request Forgery (CSRF) vulnerability in the Change Username functionality of 1Panel, an open-source Linux server management panel developed by FIT2Cloud. It affects versions 1.10.33-lts through 2.0.15 and was published on December 10, 2025, by VulnCheck. The vulnerability carries a CVSS v3.1 base score of 7.1 (High) and a CVSS v4.0 base score of 7.0 (High) (GitHub Advisory, Feedly).
The root cause is CWE-352 (Cross-Site Request Forgery): the /settings/panel endpoint responsible for changing a user's username does not implement any CSRF protections — no anti-CSRF tokens, no Origin header validation, and no Referer header validation. Because the browser automatically includes valid session cookies with cross-origin requests, an attacker can craft a malicious webpage containing a forged HTTP request targeting this endpoint. When an authenticated 1Panel user visits the attacker-controlled page, the browser silently submits the request with the victim's credentials, causing the username change to succeed without the victim's knowledge or consent (GitHub Advisory).
Successful exploitation allows an unauthenticated attacker to change an authenticated victim's 1Panel username without consent. After the username is changed, the victim is immediately logged out and cannot log back in using their original credentials, resulting in effective account lockout and denial of service. While there is no confidentiality impact (no data is exposed), the integrity of account configuration is compromised and the availability of the panel to the legitimate administrator is fully disrupted (GitHub Advisory, Feedly).
There is no public proof-of-concept exploit code and no evidence of active in-the-wild exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.018% (0.000180), placing it in a low exploitation probability tier. Exploitation requires user interaction — the victim must visit a malicious webpage while authenticated to 1Panel — which limits opportunistic mass exploitation (GitHub Advisory, Feedly).
fetch/XMLHttpRequest that submits a POST request to the victim's 1Panel instance at the /settings/panel endpoint with a desired new username as the payload./settings/panel (or equivalent username-change API endpoint) originating from an unexpected IP address or Referer header pointing to an external/unknown domain.Referer header pointing to an external or unfamiliar domain, or with no Referer header at all when one would normally be expected.Users should upgrade 1Panel to a version beyond 2.0.15 that addresses this CSRF vulnerability; the latest available release is v2.1.13 as of May 2025 (1Panel Releases). As interim mitigations, administrators should implement network-level controls to restrict access to the 1Panel interface to trusted IP ranges only, reducing the attack surface. Additionally, users should be cautious about clicking external links while authenticated to 1Panel, and organizations should consider enabling SameSite cookie attributes and enforcing strict browser security policies where possible (GitHub Advisory).
The vulnerability was assigned and disclosed by VulnCheck, which published a dedicated advisory describing the account lockout impact (VulnCheck Advisory). The GitHub Advisory Database reviewed and published the advisory on December 10, 2025. No significant broader media coverage, researcher commentary, or notable social media discussion has been identified for this vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."