First published: Thu Jan 05 2023(Updated: )
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Control-webpanel Webpanel | <0.9.8.1147 | |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-44877 is a vulnerability in CWP Control Web Panel that allows remote attackers to execute commands via shell metacharacters in the login parameter.
CVE-2022-44877 allows remote attackers to execute commands on CWP Control Web Panel.
The severity of CVE-2022-44877 is high.
To fix CVE-2022-44877, update CWP Control Web Panel to the latest version provided by the vendor.
More information about CVE-2022-44877 can be found at the following link: [https://control-webpanel.com/changelog#1669855527714-450fb335-6194](https://control-webpanel.com/changelog#1669855527714-450fb335-6194)