Record summary

CVE-2021-31324 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Execution.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryCRITICALCentOS Web Panel - OS Command InjectionCVSS 9.8

The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Execution.

Impact

Unauthenticated attackers can execute arbitrary OS commands with root privileges via command injection in the idsession parameter, leading to complete server compromise.

Remediation

Apply security updates provided by CentOS Web Panel.

WeaknessesCWE-78
Authorsritikchaddha
Template tagscvecve2021centoscwpsrvosrcevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:control-webpanel:webpanel:-:*:*:*:*:*:*:*
Shodan: title:"Login | Control WebPanel"
FOFA: title="Login | Control WebPanel"

Source: ProjectDiscovery

References

2