Security Vulnerabilities fixed in Control Web Panel 0.9.8.1147

description-logoDescription

CWP (Control Web Panel) versions before 0.9.8.1147 allow remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter, enabling remote code execution.

description-logoOutbreak Alert

A command injection vulnerability that allows remote attackers to easily exploit CWP (Control Web Panel) with a crafted HTTP request which can result in Remote Code Execution. According to Shodan, there are thousands of servers that could still be vulnerable to CVE-2022-44877. This vulnerability can be leveraged to perform ransomware attacks or exfiltration of data.

View the full Outbreak Alert Report

affected-products-logoAffected Applications

Control Web Panel

Version Updates

Date Version Status Detail
2026-02-21 2.00700
New
Control Web Panel
2024-12-05 2.00521
Modified
Control Web Panel
2023-01-13 2.00135
New
GitLab