top of page
perceptive_background_267k.jpg

Control Web Panel before 0.9.8.1225 contains a blind SQL injection vulnerability that allows unauthenticated remote attackers to execute arbitrary SQL queries b…

Published:

30 juni 2026 om 22:00:00

Alert date:

1 juli 2026 om 17:07:03

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Database & Storage, Zero-Day Vulnerabilities

Control Web Panel versions before 0.9.8.1225 contain a blind SQL injection vulnerability in the userRes POST parameter at the user endpoint. The flaw allows unauthenticated remote attackers to execute arbitrary SQL queries without any authentication. Attackers can leverage MySQL root privileges obtained through the injection to write arbitrary files using the INTO DUMPFILE directive. This capability enables the deployment of a PHP webshell to the web-accessible roundcube logs directory. Successful exploitation results in remote code execution running as the cwpsvc account. The vulnerability chain effectively provides full server compromise from an unauthenticated network position. A patch is available in version 0.9.8.1225 and later.

Technical details

Mitigation steps:

Affected products:

Control Web Panel (CWP) before 0.9.8.1225

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page