#VU29326 SQL injection in CentOS Web Panel
Published: June 26, 2020
CentOS Web Panel
CentOS Web Panel
Description
The vulnerability allows a remote attacker to execute arbitrary SQL queries in database.
The vulnerability exists due to insufficient sanitization of user-supplied data in the "username" parameter in "ajax_list_accounts.php". A remote attacker can send a specially crafted request to the affected application and gain access to sensitive information on the target system.