QID 730938
Date Published: 2023-10-26
QID 730938: Centos Web Panel Multiple Vulnerabilities
Control Web Panel is a free modern and intuitive control panel for servers and VPS that enables the day to day management and their security easy.
This indicates an attack attempt to exploit a Directory Traversal vulnerability in CentOS Web Panel. The vulnerability is due to an error in the vulnerable application when handling a maliciously crafted request.
Affected Version :
CentOS Web Panel 0.9.8.480
QID Detection Logic (Un-Auth):
This QID send GET request to /admin/index.php module=file_editor to check for sensitive information disclosure.
A remote attacker may be able to exploit this to read arbitrary file on the system.
Solution
Vendor has released fix for this. Refer to CWP web page here for updates and patch information.
Vendor References
CVEs related to QID 730938
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Control Web Panel |
|