S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 21, 2025

CVE-2021-31316 Scanner

CVE-2021-31316 Scanner - SQL Injection vulnerability in CentOS Web Panel

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.1k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
3
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-31316
9.8
CVSS

The unprivileged user portal part of CentOS Web Panel is affected by a SQL Injection via the 'idsession' HTTP POST parameter.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 19, 2026View on NVD →
Detail

CentOS Web Panel (CWP) is a widely used control panel designed for web hosting management. It simplifies the administration of Linux servers, providing an intuitive interface for managing domains, file storage, and server configurations. CWP is commonly used by web hosting providers and system administrators for efficient server management.

This vulnerability allows attackers to exploit a SQL Injection (SQLi) flaw in the `idsession` parameter of the `login/index.php` endpoint. By crafting malicious SQL statements, attackers can execute unauthorized queries on the underlying database. This issue arises from improper input validation in handling user-supplied data.

Technical analysis shows that the vulnerability exists in the HTTP POST parameter `idsession`. Attackers can inject SQL payloads that interact with the database, potentially exposing sensitive data or altering database contents. This critical vulnerability can be exploited remotely without prior authentication.

If successfully exploited, this vulnerability can lead to unauthorized data access, modification, or deletion. Attackers may retrieve sensitive information, such as user credentials, or compromise the entire database structure. The potential impact includes service disruption, data leaks, and significant reputational harm for affected organizations.

REFERENCES

Solution Advice
  • Update CentOS Web Panel to the latest version that patches this vulnerability.
  • Implement robust input validation to prevent SQL Injection attacks.
  • Use parameterized queries or prepared statements for database interactions.
  • Restrict access to the user portal and enable IP whitelisting for critical endpoints.
  • Monitor server and database logs for suspicious activity indicating potential exploitation.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-31316 Scanner - SQL Injection vulnerability in CentOS Web Panel | S4E