PT-2023-5686 · Unknown · Control Web Panel

Muhammad Ikhsanudin

·

Publicado

2023-05-09

·

Atualizado

2025-08-09

·

CVE-2023-42121

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Control Web Panel (CWP) (affected versions not specified)
Description The issue is related to a lack of proper authentication in the web interface of Control Web Panel, allowing remote attackers to execute arbitrary code on affected installations. This can impact the confidentiality, integrity, and availability of protected information. The specific flaw exists within the implementation of authentication, resulting from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to execute code in the context of a valid CWP user.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Missing Authentication

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-06354
CVE-2023-42121
ZDI-23-1478

Produtos afetados

Control Web Panel