CWP Control Web Panel OS Command Injection Vulnerability
CWP · Control Web Panel
Date added (CISA)
2023-01-17
Remediation due
2023-02-07
Known ransomware use
Not indicated
Remediation priority
P2 — past CISA due date
Description
CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command injection vulnerability that allows remote attackers to execute commands via shell metacharacters in the login parameter.