CVE-2021-31324 Scanner

Targets the idsession parameter in login/index.php of CentOS Web Panel, allowing unauthenticated attackers to execute arbitrary OS commands with root privileges.

Short Info


Level

Critical

Single Scan

Single Scan

Can be used by

Asset Owner

Estimated Time

10 seconds

Time Interval

3 weeks 17 hours

Scan only one

Domain, IPv4, Subdomain

Toolbox

CentOS Web Panel (CWP) is a free, open-source web hosting control panel widely used by system administrators and hosting providers to manage server resources, domains, email accounts, and databases. It provides a graphical interface for Linux server management, simplifying tasks like Apache configuration, DNS management, and firewall setup. CWP is popular in shared hosting environments due to its ease of use and comprehensive feature set.

CVE-2021-31324 is a critical OS Command Injection vulnerability in CentOS Web Panel. It arises from improper sanitization of user-supplied input in the unprivileged user portal. Attackers can inject arbitrary operating system commands through a vulnerable parameter, which are then executed with root privileges due to insufficient input validation and lack of proper escaping.

The vulnerability specifically affects the `idsession` parameter in the `login/index.php` endpoint. By sending a crafted HTTP request with malicious payloads in this parameter, an unauthenticated attacker can inject commands that are executed by the server. The lack of input filtering allows direct injection of shell metacharacters, enabling remote code execution without authentication.

If exploited, this vulnerability can lead to full system compromise, including unauthorized access to sensitive data, installation of malware, creation of backdoor accounts, and complete control over the affected server. Given the CVSS score of 9.8, it poses a severe risk to hosting environments, potentially affecting thousands of websites and users.

Get started to protecting your digital assets