QID 730694
Date Published: 2023-01-31
QID 730694: CWP7 (Control Web Panel 7 or CentOS Web Panel 7) Remote Code Execution (RCE) Vulnerability
CentOS Web Panel is vulnerable to Unauthenticated Remote Code Execution Vulnerability. An unauthenticated attacker can send a POST request to /login/index.php along with default credentials to trigger code execution.
Affected Versions:
CentOS Web Panel versions prior to v0.9.8.1147
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable CWP7 servers by sending a crafted payload to the server. A vulnerable server tries to connect back to the Qualys scanner on specified port. Please note that a target will only be flagged as vulnerable if it connects back to our scanner.
Successful exploitation of the vulnerability may result in remote code execution and complete system compromise.
Solution
Vendor has released patch. Customers are advised to upgrade to latest version, for more details please refer to CWP 7 Changelog
Vendor References
- Control Web Panel Changelog -
control-webpanel.com/changelog#1674073133745-84af1b53-c121
CVEs related to QID 730694
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| NA |
|