Umbra Wiki cve cve/CVE-2022-44877
Back to wiki

CVE-2022-44877 — CWP Control Web Panel OS Command Injection Vulnerability

provenance: imported · CVE: CVE-2022-44877

CVE-2022-44877: CWP Control Web Panel OS Command Injection Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project CWP
Product Control Web Panel
Date added 2023-01-17
Due date 2023-02-07
Ransomware campaign use Unknown

Description

CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command injection vulnerability that allows remote attackers to execute commands via shell metacharacters in the login parameter.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://control-webpanel.com/changelog#1669855527714-450fb335-6194; https://nvd.nist.gov/vuln/detail/CVE-2022-44877

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2022-44877
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog