Home / os / linux

Control Web Panel Unauthenticated Remote Command Execution

Posted on 31 January 2023

Control Web Panel versions prior to 0.9.8.1147 are vulnerable to unauthenticated OS command injection. Successful exploitation results in code execution as the root user. The results of the command are not contained within the HTTP response and the request will block while the command is running.

 

TOP