685
VMScore

CVE-2018-18772

Published: 20/11/2018 Updated: 24/01/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

CentOS-WebPanel.com (aka CWP) CentOS Web Panel up to and including 0.9.8.740 allows CSRF via admin/index.php?module=send_ssh, as demonstrated by executing an arbitrary OS command.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

control-webpanel webpanel

Exploits

# Title: CentOS Web Panel Root Account Takeover + Remote Command Execution <= v098740 # Author: InfinitumIT (infinitumitcomtr) # Vendor Homepage: centos-webpanelcom # Software Link: centos-webpanelcom/cwp-latest # Version: Up to v098740 # CVE: CVE-2018-18773, CVE-2018-18772 and CVE-2018-18774 #? Detailed: numan ...
CentOS Web Panel versions 098740 and below suffer from cross site request forgery and cross site scripting vulnerabilities that can be leveraged to achieve remote root command execution ...