Vulnerabilities > CVE-2020-15623 - Exposed Dangerous Method or Function vulnerability in Control-Webpanel Webpanel 0.9.8.923

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
control-webpanel
CWE-749
critical

Summary

This vulnerability allows remote attackers to write arbitrary files on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_mod_security.php. When parsing the archivo parameter, the process does not properly validate a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-9722.

Vulnerable Configurations

Part Description Count
Application
Control-Webpanel
1

Common Weakness Enumeration (CWE)