Blind SQL Injection in Control Web Panel Affects Web Management Services
⚠️ CVE-Referenzen:
CVE-2026-57517
Control Web Panel - Control Web Panel - CRITICAL - CVE-2026-57517.
The vulnerability in Control Web Panel allows unauthenticated attackers to exploit a blind SQL injection flaw. By submitting unsanitized input through the userRes POST parameter at the user endpoint, attackers can execute arbitrary SQL queries. This exploit can lead to unauthorized access to MySQL root privileges, allowing attackers to write arbitrary files to the web-accessible directory. By leveraging the INTO DUMPFILE SQL command, an attacker can deploy a PHP web shell, facilitating remote code execution under the cwpsvc account.
BADGES: 👾 EXPLOITED | 🟡 PoC | SecurityVulnerability.io
Quelle: securityvulnerability.io