CyberRota Analysis
AI-GeneratedNginx Proxy Manager versions up to 2.16.0 are vulnerable due to improper access controls on the advanced_config field, enabling non-admin users with manage permissions to inject arbitrary nginx directives. This flaw allows attackers to manipulate nginx configurations, potentially serving unauthorized files or altering routing for their assigned hosts. Organizations using Nginx Proxy Manager should prioritize this vulnerability to mitigate the risk of unauthorized access and potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Nginx Proxy Manager through 2.16.0 fails to restrict the advanced_config field to administrators, allowing non-admin users with manage permissions to inject arbitrary nginx directives. Attackers can inject malicious nginx configuration such as alias directives to serve arbitrary files or control routing for their assigned hosts.