CVE-2018-18322 describes a critical command injection vulnerability affecting CentOS Web Panel (CWP) version 0.9.8.480. Attackers can exploit this flaw by injecting shell metacharacters into specific service parameters within the admin/index.php interface, impacting the control-webpanel product. The vulnerability carries a CVSS score of 9.8 (CRITICAL), indicating it is easily exploitable over the network without authentication or user interaction, leading to complete compromise of confidentiality, integrity, and availability. This high severity is further reflected in its FAUCET Risk Score of 97/100. While not listed on the CISA KEV catalog or Hot List, an ExploitDB entry (EDB-45610) confirms the existence of public exploit code. Despite this, there is minimal community discussion or media coverage, suggesting it is not widely exploited in the wild, though the potential for exploitation remains high.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.9.8.480CPE matchmatch criteria | cpe:2.3:a:control-webpanel:webpanel:0.9.8.480:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.