Executive brief
CWP Control Web Panel (formerly CentOS Web Panel) 7 before version 0.9.8.1147 contains an OS command injection vulnerability in login/index.php. Remote attackers can execute arbitrary OS commands via shell metacharacters in the login parameter without authentication.
Affected products
- Control Web Panel (formerly CentOS Web Panel) Control Web Panel (CWP) 7 before 0.9.8.1147
Timeline
- 2023-01-11: disclosed: Initial analysis by NIST
- 2023-01-17: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-01-17: advisory: NVD publication date