[GH-ISSUE #2733] NginxProxyManager 2.0.0~2.9.19 have command execute inject vulnerability!! #1879

Closed
opened 2026-02-26 07:32:53 +03:00 by kerem · 1 comment
Owner

Originally created by @LinuxProgramDevelop on GitHub (Mar 22, 2023).
Original GitHub issue: https://github.com/NginxProxyManager/nginx-proxy-manager/issues/2733

Describe the bug
I found a command injection vulnerability in nginx-proxy-manager, because the backend
code does not filter user input, an attacker can exploit this vulnerability to obtain
permissions, due to the different deployment methods of the old and new versions, the
corresponding container permissions/server permissions can be obtained

Nginx Proxy Manager Version
2.0.0~2.9.19

To Reproduce
report link: github.com/LinuxProgramDevelop/NginxProxyManagerCommandInjectVulnInfo@b8c4eebbb9/Nginx_proxy_manager_Command_Inject_vulnerability.pdf

Expected behavior
add a ssl cert

Operating System
docker

Originally created by @LinuxProgramDevelop on GitHub (Mar 22, 2023). Original GitHub issue: https://github.com/NginxProxyManager/nginx-proxy-manager/issues/2733 <!-- --> **Describe the bug** I found a command injection vulnerability in nginx-proxy-manager, because the backend code does not filter user input, an attacker can exploit this vulnerability to obtain permissions, due to the different deployment methods of the old and new versions, the corresponding container permissions/server permissions can be obtained **Nginx Proxy Manager Version** 2.0.0~2.9.19 **To Reproduce** report link: https://github.com/LinuxProgramDevelop/NginxProxyManagerCommandInjectVulnInfo/blob/b8c4eebbb9be81cf02679aee5207cae95137e1f5/Nginx_proxy_manager_Command_Inject_vulnerability.pdf **Expected behavior** add a ssl cert **Operating System** docker
kerem 2026-02-26 07:32:53 +03:00
  • closed this issue
  • added the
    bug
    label
Author
Owner

@blackstormlab commented on GitHub (Mar 22, 2023):

nobody except for you is supposed to access it though so while this may be possible i don't see this as anything major

<!-- gh-comment-id:1480397201 --> @blackstormlab commented on GitHub (Mar 22, 2023): nobody except for you is supposed to access it though so while this may be possible i don't see this as anything major
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/nginx-proxy-manager-NginxProxyManager#1879
No description provided.