Skip to content
COOEY

EXPOSURES › CVE-2022-44877

CVE-2022-44877

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-01-17 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-44877 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

CWP Control Web Panel OS Command Injection Vulnerability actively exploited

CWP Control Web Panel, a web hosting management panel, had an OS command injection vulnerability that allowed remote attackers to execute arbitrary commands via shell metacharacters in the login parameter, leading to potential unauthorized access and data breaches.

Shame score — Active exploitation indicates negligence in security updates and response, leading to potential unauthorized access and data breaches.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command injection vulnerability that allows remote attackers to execute commands via shell metacharacters in the login parameter.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.