CVE-2022-25048: OS Command Injection
Published Jul 7, 2022
·Updated
Command injection vulnerability in CWP v0.9.8.1126 that allows normal users to run commands as the root user.
Affected Software
1 affected component
Control-webpanel Webpanel=0.9.8.1126
Event History
Jul 7, 2022
CVE Published
via MITRE·11:29 AM
Data Sourced
via MITRE·11:29 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-25048?
CVE-2022-25048 is classified as a critical severity vulnerability because it allows normal users to execute commands as the root user.
2
How do I fix CVE-2022-25048?
To fix CVE-2022-25048, it is recommended to upgrade Control Web Panel to version 0.9.8.1127 or later.
3
Who is affected by CVE-2022-25048?
CVE-2022-25048 affects users of Control Web Panel version 0.9.8.1126.
4
What types of vulnerabilities does CVE-2022-25048 represent?
CVE-2022-25048 represents a command injection vulnerability that can lead to arbitrary code execution.
5
What could an attacker do with CVE-2022-25048?
An attacker could exploit CVE-2022-25048 to run arbitrary commands on the server with root privileges.