First published: Tue Nov 20 2018(Updated: )
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=send_ssh, as demonstrated by executing an arbitrary OS command.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CWP Control Web Panel | <=0.9.8.740 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-18772 is classified as a high-severity vulnerability due to its potential for remote command execution via CSRF.
To fix CVE-2018-18772, upgrade CentOS Web Panel to a version later than 0.9.8.740 where the vulnerability has been addressed.
CVE-2018-18772 allows an attacker to execute arbitrary OS commands on the affected server through a CSRF attack.
CVE-2018-18772 affects CentOS Web Panel versions up to and including 0.9.8.740.
You can check if your system is vulnerable to CVE-2018-18772 by verifying whether you are using CentOS Web Panel version 0.9.8.740 or earlier.