Database/Control plane, storage & DevOps

CyberPower PowerPanel Business Edition 3.4.0 Agent/Center: Cross-site request forgery across all forms in the web
Impact
Cross-site request forgery across all forms in the web application. An authenticated facility user visiting an attacker-controlled page silently submits changes to the UPS management configuration - including shutdown behaviour. Old and unglamorous, but this software persists in production far longer than anything on the compute side.
Who can reach it
Requires an authenticated PowerPanel user to visit a page the attacker controls.
What to do
Upgrade past 3.4.0. If you are still running 3.x, the more useful action is a full inventory of power-management software versions - CyberPower's 2023-2025 CVE history means anything this old is carrying many more unlisted problems.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.