Known Vulnerabilities for Webpanel by Control-webpanel
Listed below are 10 of the newest known vulnerabilities associated with "Webpanel" by "Control-webpanel".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-44877 json | login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arb... | 9.8 - CRITICAL | 2023-01-05 | 2023-04-06 |
| CVE-2022-25048 json | Command injection vulnerability in CWP v0.9.8.1126 that allows normal users to run commands as the root user. | 8.8 - HIGH | 2022-07-07 | 2022-07-14 |
| CVE-2022-25047 json | The password reset token in CWP v0.9.8.1126 is generated using known or predictable values. | 5.9 - MEDIUM | 2022-07-07 | 2023-01-24 |
| CVE-2022-25046 json | A path traversal vulnerability in loader.php of CWP v0.9.8.1122 allows attackers to execute arbitrary code via a crafted POST... | 9.8 - CRITICAL | 2022-07-07 | 2023-01-24 |
| CVE-2021-45467 json | In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause ... | 9.8 - CRITICAL | 2022-12-26 | 2023-01-24 |
| CVE-2021-45466 json | In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=add_se... | 9.8 - CRITICAL | 2022-12-26 | 2023-01-24 |
| CVE-2021-31324 json | The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote... | 9.8 - CRITICAL | 2021-05-18 | 2023-01-24 |
| CVE-2021-31316 json | The unprivileged user portal part of CentOS Web Panel is affected by a SQL Injection via the 'idsession' HTTP POST parameter. | 9.8 - CRITICAL | 2021-05-18 | 2023-01-24 |
| CVE-2020-15628 json | This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cw... | 7.5 - HIGH | 2020-07-28 | 2023-01-24 |
| CVE-2020-15627 json | This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cw... | 7.5 - HIGH | 2020-07-28 | 2023-01-24 |