Product
nginx-ui: Multiple Vulnerabilities
4 TTPsMultiple vulnerabilities in nginx-ui allow an attacker to execute arbitrary code, including with root privileges, gain elevated privileges, perform account takeover, bypass security measures, and disclose or manipulate data.
nginx-ui Information Disclosure Vulnerability
2 rules 1 TTPA remote, authenticated attacker can exploit a vulnerability in nginx-ui to disclose sensitive information.
Nginx-UI Unauthenticated Remote Code Execution via Backup Restore
2 rules 2 TTPsNginx-UI is vulnerable to unauthenticated remote code execution (RCE) via the `POST /api/restore` endpoint, allowing attackers to inject arbitrary commands into the configuration.
Unauthenticated Remote Takeover of Nginx-UI via MCP Endpoint
2 rules 5 TTPs 1 IOCNginx-UI is vulnerable to unauthenticated remote takeover due to a missing authentication check on the `/mcp_message` endpoint, allowing attackers to invoke MCP tools without authentication, leading to arbitrary nginx configuration modification, traffic interception, service disruption, configuration exfiltration, and credential harvesting; the default empty IP whitelist allows access from any network attacker.
nginx-ui Race Condition Leads to Data Corruption and Potential RCE
3 rules 2 TTPsThe nginx-ui application is vulnerable to a race condition due to concurrent requests corrupting the app.ini configuration file, potentially leading to a persistent denial of service and a non-deterministic path to remote code execution.
Nginx-UI SSRF Vulnerability via Cluster Node Proxy
2 rules 1 TTPNginx-UI version 2.3.4 and earlier is vulnerable to Server-Side Request Forgery (SSRF) allowing authenticated users to access internal services by manipulating cluster node configurations.
nginx-ui Backup Restore Allows Tampering with Encrypted Backups
3 rules 2 TTPsThe nginx-ui backup restore mechanism allows attackers to tamper with encrypted backup archives and inject malicious configuration during restoration, potentially leading to arbitrary command execution.