Record summary

CVE-2021-31316 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The unprivileged user portal part of CentOS Web Panel is affected by a SQL Injection via the 'idsession' HTTP POST parameter.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryCRITICALCentOS Web Panel - SQL InjectionCVSS 9.8

The unprivileged user portal part of CentOS Web Panel is affected by a SQL Injection via the 'idsession' HTTP POST parameter.

Impact

Unauthenticated attackers can exploit SQL injection via the idsession parameter to extract database contents or execute arbitrary commands with root privileges.

Remediation

Apply security updates provided by CentOS Web Panel.

WeaknessesCWE-89
Authorsritikchaddha
Template tagscvecve2021centoscwpsrvsqlivuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:control-webpanel:webpanel:-:*:*:*:*:*:*:*
Shodan: title:"Login | Control WebPanel"
FOFA: title="Login | Control WebPanel"

Source: ProjectDiscovery

References

2