QID 150642
Date Published: 2023-02-06
QID 150642: Control Web Panel 7 (CWP7) Unauthenticated Remote Code Execution (RCE) Vulnerability (CVE-2022-44877)
Control Web Panel (CWP or CentOS Web Panel) is a free modern and intuitive control panel for servers and VPS Linux software.
Affected versions of CWP suffer from an operating system command injection via shell metacharacters in "login" parameter on the "/login/index.php" endpoint.
Affected Versions:
Control Web Panel versions prior to 0.9.8.1147
QID Detection Logic (Authenticated):
This QID sends a HTTP GET request and checks for vulnerable version of Control Web Panel running on the target server.
Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to execute arbitrary code on the target system.
Solution
Customers are advised to upgrade to Control Web Panel version 0.9.8.1147 or later to remediate this vulnerability. For more information regarding this vulnerability please refer to CWP Changelog
Vendor References
- Control Web Panel Changelog -
control-webpanel.com/changelog#1674073133745-84af1b53-c121
CVEs related to QID 150642
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Control Web Panel Downloads |
|