Showing 1 vulnerability on this page for webpanel

Signals CISA KEV Ransomware Nuclei
control-webpanel vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Control Web Panel (CWP), CentOS Web Panel Preauth Remote Code Execution

In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.php to register an arbitrary API key, as demonstrated by a /user/loader.php?api=1&scripts= .%00./.%00./api/account_new_create&acc=guadaapi URI. Any number of %00 instances can be used, e.g., .%00%00%00./.%00%00%00./api/account_new_create could also be used for the scripts parameter.

CWE-862Dec 26, 20221 related artifact
CVSS9.8v3.1EPSS70.9%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX