EXPOSURES › CVE-2022-44877
CVE-2022-44877
HIGH ⌖ ON CISA KEV · EXPLOITEDCWP Control Web Panel OS Command Injection Vulnerability actively exploited
CWP Control Web Panel, a web hosting management panel, had an OS command injection vulnerability that allowed remote attackers to execute arbitrary commands via shell metacharacters in the login parameter, leading to potential unauthorized access and data breaches.
Shame score — Active exploitation indicates negligence in security updates and response, leading to potential unauthorized access and data breaches.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command injection vulnerability that allows remote attackers to execute commands via shell metacharacters in the login parameter.