important · Remote code execution
A Virtualizor billing callback can turn an unauthenticated request into root execution on the hypervisor.
Affects
Softaculous Virtualizor, a Linux-hosted VPS and hypervisor control panel whose administrative web process runs as root.
The path requires exposed administrative ports, in-house billing and an eligible suspended account. MySQL coerces the numeric prefix of a shell-bearing uid while the original string survives into a command executed by the root PHP-FPM pool.
Detail and 2 sources
A public exploit module exists, and a researcher retested the vendor fixes on September 20. The fix was not read for this brief, so the item cannot lead.