nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-31324 CVE-2021-31324
CRITICALNuclei
CentOS Web Panel - OS Command Injection
Record summary
CVE-2021-31324 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Execution.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryCRITICALCentOS Web Panel - OS Command InjectionCVSS 9.8
The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Execution.
Impact
Unauthenticated attackers can execute arbitrary OS commands with root privileges via command injection in the idsession parameter, leading to complete server compromise.
Remediation
Apply security updates provided by CentOS Web Panel.
WeaknessesCWE-78
Authorsritikchaddha
Template tagscvecve2021centoscwpsrvosrcevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:control-webpanel:webpanel:-:*:*:*:*:*:*:*
Shodan: title:"Login | Control WebPanel"
FOFA: title="Login | Control WebPanel"
https://www.shielder.com/advisories/centos-web-panel-idsession-root-rce/ https://nvd.nist.gov/vuln/detail/CVE-2021-31324
Source: ProjectDiscovery
References
2shielder.it
https://www.shielder.it/advisories/centos-web-panel-idsession-root-rce