nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-31316 CVE-2021-31316
CRITICALNuclei
CentOS Web Panel - SQL Injection
Record summary
CVE-2021-31316 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
The unprivileged user portal part of CentOS Web Panel is affected by a SQL Injection via the 'idsession' HTTP POST parameter.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryCRITICALCentOS Web Panel - SQL InjectionCVSS 9.8
The unprivileged user portal part of CentOS Web Panel is affected by a SQL Injection via the 'idsession' HTTP POST parameter.
Impact
Unauthenticated attackers can exploit SQL injection via the idsession parameter to extract database contents or execute arbitrary commands with root privileges.
Remediation
Apply security updates provided by CentOS Web Panel.
WeaknessesCWE-89
Authorsritikchaddha
Template tagscvecve2021centoscwpsrvsqlivuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:control-webpanel:webpanel:-:*:*:*:*:*:*:*
Shodan: title:"Login | Control WebPanel"
FOFA: title="Login | Control WebPanel"
https://www.shielder.com/advisories/centos-web-panel-idsession-root-rce/ https://nvd.nist.gov/vuln/detail/CVE-2021-31316
Source: ProjectDiscovery
References
2shielder.it
https://www.shielder.it/advisories/centos-web-panel-idsession-root-rce