PT-2018-14405 · Centos · Centos Web Panel

Published

2018-10-15

·

Updated

2023-01-24

·

CVE-2018-18322

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CentOS Web Panel version 0.9.8.480
Description The issue concerns Command Injection via shell metacharacters in the admin/index.php API endpoint, specifically in the service start, service restart, service fullstatus, or service stop parameters. This allows for potential command injection attacks.
Recommendations For version 0.9.8.480, consider disabling the service start, service restart, service fullstatus, and service stop parameters in the admin/index.php endpoint until a patch is available. Restrict access to the admin/index.php endpoint to minimize the risk of exploitation. Avoid using the service start, service restart, service fullstatus, and service stop parameters in the affected API endpoint until the issue is resolved.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2018-18322

Affected Products

Centos Web Panel