Known Vulnerabilities for Webpanel by Control-webpanel
Listed below are 10 of the newest known vulnerabilities associated with "Webpanel" by "Control-webpanel".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-25048 | Command injection vulnerability in CWP v0.9.8.1126 that allows normal users to run commands as the root user. | 8.8 - HIGH | 2022-07-07 | 2022-07-14 |
| CVE-2022-25047 | The password reset token in CWP v0.9.8.1126 is generated using known or predictable values. | 5.9 - MEDIUM | 2022-07-07 | 2023-01-24 |
| CVE-2022-25046 | A path traversal vulnerability in loader.php of CWP v0.9.8.1122 allows attackers to execute arbitrary code via a crafted POST... | 9.8 - CRITICAL | 2022-07-07 | 2023-01-24 |
| CVE-2021-31324 | The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote... | 9.8 - CRITICAL | 2021-05-18 | 2023-01-24 |
| CVE-2021-31316 | The unprivileged user portal part of CentOS Web Panel is affected by a SQL Injection via the 'idsession' HTTP POST parameter. | 9.8 - CRITICAL | 2021-05-18 | 2023-01-24 |
| CVE-2020-15423 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.... | 9.8 - CRITICAL | 2020-07-28 | 2023-01-24 |
| CVE-2020-15422 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.... | 9.8 - CRITICAL | 2020-07-28 | 2023-01-24 |
| CVE-2020-15421 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.... | 9.8 - CRITICAL | 2020-07-28 | 2023-01-24 |
| CVE-2020-15420 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-el7-0.... | 9.8 - CRITICAL | 2020-07-28 | 2023-01-24 |
| CVE-2020-10230 | CentOS-WebPanel.com (aka CWP) CentOS Web Panel (for CentOS 6 and 7) allows SQL Injection via the /cwp_{SESSION_HASH}/admin/lo... | 9.8 - CRITICAL | 2020-03-16 | 2023-01-24 |