S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-44877 Scanner

CVE-2022-44877 scanner - OS Command Injection vulnerability in CWP (aka Control Web Panel or CentOS Web Panel) 7

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.5k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2022-44877
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

CWP (aka Control Web Panel or CentOS Web Panel) 7 is a popular web hosting control panel designed for CentOS servers. It is widely used by small and medium-sized businesses and individual website owners for managing their web hosting accounts, domains, and DNS settings. The control panel comes with a simple web interface that allows users to easily configure and manage their web hosting accounts without any technical knowledge or expertise. CWP also provides many advanced features for managing websites, databases, and email accounts, making it one of the most powerful and easy-to-use control panels available today.

One of the latest vulnerabilities detected in CWP is CVE-2022-44877, which allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter. This vulnerability can be exploited through a variety of means, such as social engineering, phishing attacks, or exploiting compromised accounts. Once exploited, attackers can gain unauthorized access to sensitive data, install malware, or take over the server and use it for malicious purposes.

When this vulnerability is exploited, it can lead to serious consequences for web hosting companies and their customers. Attackers can steal information, damage reputation, and even cause financial losses. Moreover, exploited servers can be used for launching further attacks against other targets, turning them into a part of a botnet that can be hard to detect and eliminate.

s4e.io is an online platform that offers advanced security tools and services to help businesses protect their digital assets from cyber threats. Thanks to the pro features of the s4e.io platform, those who read this article can easily and quickly learn about vulnerabilities in their digital assets. The platform provides real-time alerts, reports, and analytics that help users identify and mitigate security risks before they can be exploited. With s4e.io, businesses can rest assured that their digital assets are secure from any potential threats.

 

REFERENCES

Solution Advice

To protect against this vulnerability, web hosting providers should take the following precautions:

  • Immediately apply the latest updates and security patches provided by CWP, which will fix the vulnerability.
  • Monitor their servers for any signs of suspicious activity, such as unusual login attempts or high resource usage.
  • Use strong passwords and two-factor authentication to secure accounts and prevent unauthorized access.
  • Educate their customers about the risks of phishing and social engineering attacks and how to protect against them.
  • Conduct regular security audits and vulnerability assessments to identify and mitigate security risks before they can be exploited.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.