Critical Bugs in CentOS Web Panel Expose Linux Servers to RCE Attacks

Critical Bugs in CentOS Web Panel Expose Linux Servers to RCE Attacks

Researchers have discovered two severe security flaws in the CentOS Web Panel that might be used as part of an exploit chain to gain pre-authenticated remote code execution on affected hosts.CentOS logo

Control Web Panel, formerly CentOS Web Panel, is a free and open-source Linux control panel for setting up web hosting settings.

The vulnerability, which has been assigned the number CVE-2021-45467, is a file inclusion vulnerability, which happens when a web app is tricked to expose or run arbitrary files on the webserver.


According to Paulos Yibelo of Octagon Networks, who identified and reported the issues, the problem occurs when two of the application’s unauthenticated PHP pages — “/user/login.php” and “/user/index.php” — fail to sufficiently validate a path to a script file.

This means that an attacker only needs to change the include statement, which is used to incorporate the content of one PHP file into another PHP file, to inject malicious code from a remote resource and gain code execution.

Interestingly, while the program had protections in place to signal attempts to switch to a parent directory (denoted by “..”) as a “hacking attempt,” it did nothing to stop the PHP interpreter from accepting a specifically generated text. “$00.” and effectively bypassing the application.

This not only allows a bad actor to acquire access to restricted API endpoints but can also be combined with an arbitrary file write vulnerability (CVE-2021-45466) to gain complete remote code execution on the server.

The CWP maintainers have since corrected the problems with fixes released earlier this month, following appropriate disclosure.

A Free, Human-Built Website — Included with Every Hosting Plan

Sign up for any annual  hosting plan and get a custom-built, 4-page WordPress site. Yes, an actual web designer will create a professional, m...
8 min read
Walter Akolo
Walter Akolo
Hosting Expert

DreamHost in Europe: Local Hosting, Faster Servers, and Smarter Tools

now runs in Europe (Amsterdam). Until now, DreamHost’s infrastructure was anchored in Ashburn, Virginia, and Hillsboro, Oregon. The addition o...
6 min read
Walter Akolo
Walter Akolo
Hosting Expert

FastComet Simplifies Magento 2.4 Search with Built-In Elasticsearch Integration

If you're running or planning to upgrade to Magento 2.4, you’ll need Elasticsearch. It’s a mandatory requirement. Magento 2.4 won’t install or upg...
3 min read
Walter Akolo
Walter Akolo
Hosting Expert

FastComet Launches a Marketplace with Cloud Apps and Hosting Add-Ons

FastComet has introduced a major upgrade to its hosting experience with the launch of the —a centralized hub where you can install cloud apps, enable add-ons, and access new services in just a few clicks. Instead of navigating different parts of your dashboard or relying on emails to find out what’s new, the Marketplace brings […]
6 min read
Walter Akolo
Walter Akolo
Hosting Expert
Click to go to the top of the page
Go To Top
HostAdvice.com provides professional web hosting reviews fully independent of any other entity. Our reviews are unbiased, honest, and apply the same evaluation standards to all those reviewed. While monetary compensation is received from a few of the companies listed on this site, compensation of services and products have no influence on the direction or conclusions of our reviews. Nor does the compensation influence our rankings for certain host companies. This compensation covers account purchasing costs, testing costs and royalties paid to reviewers.