PT-2022-6101 · Unknown · Control Web Panel
Numan Turle
·
Published
2022-10-25
·
Updated
2026-04-13
·
CVE-2022-44877
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Control Web Panel versions prior to 0.9.8.1147
Description
The issue is related to the login/index.php component in Control Web Panel, which allows remote attackers to execute arbitrary OS commands via shell metacharacters in the
login parameter. This can be exploited by sending specially crafted HTTP requests. The vulnerability is under active exploit and has a high severity rating.Recommendations
For Control Web Panel versions prior to 0.9.8.1147, update to version 0.9.8.1147 or later to resolve the issue.
As a temporary workaround, consider restricting access to the login/index.php component until a patch is applied.
Avoid using the
login parameter in the affected API endpoint until the issue is resolved.Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Control Web Panel