PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Exposed Panels·Updated May 18, 2026

Control Web Panel (CWP) - File Inclusion

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsurl
CostFree
3.3k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-45467
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.php to register an arbitrary API key, as demonstrated by a /user/loader.php?api=1&scripts= .%00./.%00./api/account_new_create&acc=guadaapi URI. Any number of %00 instances can be used, e.g., .%00%00%00./.%00%00%00./api/account_new_create could also be used for the scripts parameter.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Sep 9, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

Control Web Panel (CWP) - File Inclusion CVE-2021-45467 Scanner | S4E