Security Vulnerabilities fixed in Control Web Panel 0.9.8.1147
Description
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter.
Outbreak Alert
A command injection vulnerability that allows remote attackers to easily exploit CWP (Control Web Panel) with a crafted HTTP request which can result in Remote Code Execution. According to Shodan, there are thousands of servers that could still be vulnerable to CVE-2022-44877. This vulnerability can be leveraged to perform ransomware attacks or exfiltration of data.
Affected Applications
Control Web Panel
Telemetry
Version Updates
Date | Version | Detail |
---|---|---|
2023-01-13 | 2.135 | GitLab |