CVE-2020-15606: (0Day) CentOS Web Panel ajax_admin_apis Command Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajaxadminapis.php. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-9720.
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajaxadminapis.php. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-15606?
CVE-2020-15606 is considered a critical severity vulnerability due to its ability to allow remote code execution.
How do I fix CVE-2020-15606?
To fix CVE-2020-15606, update CentOS Web Panel to the latest version that addresses this vulnerability.
What software is affected by CVE-2020-15606?
CVE-2020-15606 affects CentOS Web Panel version 0.9.8.923.
Can authentication bypass vulnerability CVE-2020-15606 be exploited remotely?
Yes, CVE-2020-15606 can be exploited remotely without the need for authentication.
What specific component is flawed in CVE-2020-15606?
The specific flaw in CVE-2020-15606 exists within the ajax_admin_apis.php component.