Back to Database
Status published
Unknown
CVE-2022-44877
login/index.php in CWP (aka Control Web Panel or CentOS Web...
Vulnerability Description
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-44877
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.youtube.com/watch?v=kiLfSvc1SYY
- https://gist.github.com/numanturle/c1e82c47f4cba24cff214e904c227386
- http://seclists.org/fulldisclosure/2023/Jan/1
- http://packetstormsecurity.com/files/170388/Control-Web-Panel-7-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/170820/Control-Web-Panel-Unauthenticated-Remote-Command-Execution.html
- http://packetstormsecurity.com/files/171725/Control-Web-Panel-7-CWP7-0.9.8.1147-Remote-Code-Execution.html
More from control-webpanel
View All →CVE-2022-25048
Command injection vulnerability in CWP v0.9.8.1126 that allows normal users...
High
8.8
CVE-2022-25047
The password reset token in CWP v0.9.8.1126 is generated using...
Medium
5.9
CVE-2022-25046
A path traversal vulnerability in loader.php of CWP v0.9.8.1122 allows...
Critical
9.8
CVE-2021-45467
In CWP (aka Control Web Panel or CentOS Web Panel)...
Unknown
0
CVE-2021-45466
In CWP (aka Control Web Panel or CentOS Web Panel)...
Unknown
0
Affected Vendor
control-webpanel
View all reports →Affected Software
webpanel
Vulnerable Versions:
0
Timeline
Official Publish:
January 5th, 2023
Last Modified:
October 21st, 2025
Added to House:
July 21st, 2026
CVSS Vectors
No vector data available
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.