First published: Thu Jul 07 2022(Updated: )
A path traversal vulnerability in loader.php of CWP v0.9.8.1122 allows attackers to execute arbitrary code via a crafted POST request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CentOS Web Panel | <=0.9.8.1124 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-25046 is classified as a critical severity vulnerability due to its ability to allow arbitrary code execution.
To fix CVE-2022-25046, update your CentOS Web Panel to version 0.9.8.1125 or later.
CVE-2022-25046 affects CentOS Web Panel versions up to and including 0.9.8.1124.
Attackers can exploit CVE-2022-25046 through crafted POST requests that leverage the path traversal vulnerability.
The risks associated with CVE-2022-25046 include the potential for unauthorized access and execution of malicious code on the server.