Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Berke Yilmaz

#37076of 53,633
7.5Total CVSS
Vulnerabilities · 1
PT-2020-11987
7.5
2020-03-16
Centos · Centos Web Panel · CVE-2020-10230
**Name of the Vulnerable Software and Affected Versions** CentOS Web Panel versions for CentOS 6 and 7 **Description** The issue allows SQL Injection via the "/cwp {SESSION HASH}/admin/loader ajax.php" API endpoint, specifically through the `term` parameter. This enables potential attackers to inject malicious SQL code. **Recommendations** For CentOS Web Panel versions for CentOS 6 and 7, consider restricting access to the "/cwp {SESSION HASH}/admin/loader ajax.php" API endpoint until a patch is available. As a temporary workaround, avoid using the `term` parameter in the affected API endpoint to minimize the risk of exploitation.