Everyone still using this thing for client management lor. I tell you lah, the security debt is real. Last month I found three hosts still on 1.x branch, no patch since 2022 already. Can?
The api auth is basically a token in a cookie. No csrf protection for the rebuild function. I pentested one host for fun, got root in twenty minutes. But clients want solusvm because familiar leh. Familiar until breach then how?
The panel code is php 5 era. Ioncube encoded so community cannot even audit. We are trusting a black box for hypervisor access. This one not hot take, this is common sense can.
Your move, defenders.