PT-2018-2679 · Centos · Centos Web Panel

Published

2018-11-05

·

Updated

2023-01-24

·

CVE-2018-18772

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions CentOS Web Panel versions through 0.9.8.740
Description The issue is related to insufficient authentication of requests, allowing for the execution of arbitrary OS commands. This can be exploited by a remote attacker to execute commands. The "admin/index.php?module=send ssh" endpoint is specifically vulnerable to this issue.
Recommendations For versions through 0.9.8.740, as a temporary workaround, consider restricting access to the "admin/index.php?module=send ssh" endpoint until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-01326
CVE-2018-18772

Affected Products

Centos Web Panel