PT-2023-5686 · Unknown · Control Web Panel
Muhammad Ikhsanudin
·
Published
2023-05-09
·
Updated
2025-08-09
·
CVE-2023-42121
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Control Web Panel (CWP) (affected versions not specified)
Description
The issue is related to a lack of proper authentication in the web interface of Control Web Panel, allowing remote attackers to execute arbitrary code on affected installations. This can impact the confidentiality, integrity, and availability of protected information. The specific flaw exists within the implementation of authentication, resulting from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to execute code in the context of a valid CWP user.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Missing Authentication
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Control Web Panel