Junglewise Threat Intelligence

CVE-2022-44877: CWP Control Web Panel OS Command Injection Vulnerability

CVE-2022-44877 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2023-01-17

Technologies: cPanel Control Web Panel. Vendors: cPanel.

Executive brief

CWP Control Web Panel (formerly CentOS Web Panel) 7 before version 0.9.8.1147 contains an OS command injection vulnerability in login/index.php. Remote attackers can execute arbitrary OS commands via shell metacharacters in the login parameter without authentication.

Affected products

  • Control Web Panel (formerly CentOS Web Panel) Control Web Panel (CWP) 7 before 0.9.8.1147

Timeline

  • 2023-01-11: disclosed: Initial analysis by NIST
  • 2023-01-17: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-01-17: advisory: NVD publication date

Related threats