Skip to main content
high CISA KEV

CVE-2022-44877

CWP Control Web Panel OS Command Injection Vulnerability

Description

CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command injection vulnerability that allows remote attackers to execute commands via shell metacharacters in the login parameter.

Required action

Apply updates per vendor instructions.

Federal remediation due Feb 7, 2023 — past due

Advertisement

Coverage

No article in the archive references CVE-2022-44877 yet. The record below is from CISA's catalog.