Security Vulnerabilities fixed in Control Web Panel 0.9.8.1147
Description
CWP (Control Web Panel) versions before 0.9.8.1147 allow remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter, enabling remote code execution.
Outbreak Alert
A command injection vulnerability that allows remote attackers to easily exploit CWP (Control Web Panel) with a crafted HTTP request which can result in Remote Code Execution. According to Shodan, there are thousands of servers that could still be vulnerable to CVE-2022-44877. This vulnerability can be leveraged to perform ransomware attacks or exfiltration of data.
Affected Applications
Control Web Panel