CVE-2018-18772: CSRF
Published Nov 20, 2018
·Updated
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=sendssh, as demonstrated by executing an arbitrary OS command.
Affected Software
1 affected component
Control-webpanel Webpanel<=0.9.8.740
Event History
Nov 20, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-18772?
CVE-2018-18772 is classified as a high-severity vulnerability due to its potential for remote command execution via CSRF.
2
How do I fix CVE-2018-18772?
To fix CVE-2018-18772, upgrade CentOS Web Panel to a version later than 0.9.8.740 where the vulnerability has been addressed.
3
What kind of attack does CVE-2018-18772 allow?
CVE-2018-18772 allows an attacker to execute arbitrary OS commands on the affected server through a CSRF attack.
4
Which software versions are affected by CVE-2018-18772?
CVE-2018-18772 affects CentOS Web Panel versions up to and including 0.9.8.740.
5
How can I determine if my system is vulnerable to CVE-2018-18772?
You can check if your system is vulnerable to CVE-2018-18772 by verifying whether you are using CentOS Web Panel version 0.9.8.740 or earlier.