← Back to browse · API

CVE-2021-45466

Severity
CRITICAL
CVSS
9.8
EPSS
0.55338
Risk score
58.57
CISA KEV
No
PoC
No
Published
2022-12-26
Modified
2025-04-14
First seen
2026-08-07
Aliases
EUVD-2021-32232, GHSA-CMWH-95WF-H584
Products
n/a:n/a n/a
Sources
euvd EUVD-2021-32232

Description

In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=add_server&DHCP= to add an authorized_keys text file in the /resources/ folder.

References