Back to Database
Status published
Medium
CVE-2022-25047
The password reset token in CWP v0.9.8.1126 is generated using...
Vulnerability Description
The password reset token in CWP v0.9.8.1126 is generated using known or predictable values.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-25047
Credits & Attribution
No credits recorded in the NVD database.
More from control-webpanel
View All →CVE-2022-44877
login/index.php in CWP (aka Control Web Panel or CentOS Web...
Unknown
0
CVE-2022-25048
Command injection vulnerability in CWP v0.9.8.1126 that allows normal users...
High
8.8
CVE-2022-25046
A path traversal vulnerability in loader.php of CWP v0.9.8.1122 allows...
Critical
9.8
CVE-2021-45467
In CWP (aka Control Web Panel or CentOS Web Panel)...
Unknown
0
CVE-2021-45466
In CWP (aka Control Web Panel or CentOS Web Panel)...
Unknown
0
Affected Vendor
control-webpanel
View all reports →Affected Software
webpanel
Vulnerable Versions:
0.9.8.1126
Timeline
Official Publish:
July 7th, 2022
Last Modified:
August 3rd, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.