Ajenti has an authorization bypass during custom package installation
An authenticated user (using the auth_users plugin authentication method) could install a custom package even if this user is not superuser.
An authenticated user (using the auth_users plugin authentication method) could install a custom package even if this user is not superuser.
Ajenti contains an Improper Error Handling vulnerability in Login JSON request that can result in a path traversal.
Ajenti contains an Information Disclosure vulnerability that can result in user and system enumeration.
Ajenti contains an Insecure Permissions vulnerability that allows normal users to download arbitrary plugins.
Ajenti contains an Input Validation vulnerability. An attacker can freeze the server by sending a long string through the ID parameter.
Ajenti contains a CSRF vulnerability in the command execution panel of the tool used to manage the server.