S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2018-18323 Scanner

CVE-2018-18323 scanner - Local File Inclusion (LFI) vulnerability in CentOS Web Panel

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.8k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-18323
7.5
CVSS

CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Local File Inclusion via directory traversal with an admin/index.php?module=file_editor&file=/../ URI.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

CentOS Web Panel is a control panel solution for hosting websites and managing server configurations. It is an open-source web hosting management platform that provides a vast range of features to its users. The tool offers a variety of options to control the entire hosting environment, including mail, DNS, databases, and more. Besides, it streamlines the installation process of several software, including Apache, PHP, Nginx, and Exim. The tool’s versatile web interface simplifies the user's tasks with its visually attractive, easy-to-use interface.

One known vulnerability detected in this product is the CVE-2018-18323. This vulnerability is caused by a Local File Inclusion vulnerability via directory traversal found with an admin/index.php?module=file_editor&file=/../ URI. This security flaw permits a user to access sensitive information outside the server root. 

If exploited, the CVE-2018-18323 vulnerability of CentOS Web Panel can cause severe damage. It can lead to the unauthorized access of a user account, comprising the affected web server. Attackers may execute arbitrary codes, delete sensitive data, and compromise the host. Any critical data stored on the servers can be lost, and malicious attackers could access the servers' confidential information.

In conclusion, the CentOS Web Panel is an all-in-one hosting management system that enables users to streamline their websites and manage their applications efficiently. However, just like other similar tools, it is important to implement the adequate security measures to reduce the vulnerability of the web server. s4e.io is a platform that offers pro features that can allow readers to learn more about vulnerabilities in their digital assets quickly and effortlessly saving time and resources.

 

REFERENCES

Solution Advice

Several precautions can protect against the CVE-2018-18323 attack. Here are a few of them:

  • Update CentOS Web Panel to the latest version.
  • Disable the admin file editor from the control panel.
  • Configure secure file permissions on the server root.
  • Use Web Application Firewall (WAF) or IDS/ IPS on external-facing applications.
  • Implement Resource Access Control on both the application and server to protect against sensitive resource access. 

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2018-18323 scanner - Local File Inclusion (LFI) vulnerability in CentOS Web Panel | S4E