CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.8. Its EPSS score suggests a 70.9% probability of exploitation in the next 30 days. Exploitation may require the attacker to be authenticated.
Original NVD Description
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.php to register an arbitrary API key, as demonstrated by a /user/loader.php?api=1&scripts= .%00./.%00./api/account_new_create&acc=guadaapi URI. Any number of %00 instances can be used, e.g., .%00%00%00./.%00%00%00./api/account_new_create could also be used for the scripts parameter.
Related CVEs
Other vulnerabilities affecting the same vendor(s)