logo

Public PoC Code Exposes CVSS 9.8 Control Web Panel SQL Injection CVE-2026-57517

ID: 0bdbc949-e4c1-5325-be7d-0fd29bca1a9a

STIX ID: report--0bdbc949-e4c1-5325-be7d-0fd29bca1a9a

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-07-03

Date Updated: 2026-08-06

Author: Do Son

ADMIRALTY:B6
...
...

A critical unauthenticated blind SQL injection (CVE-2026-57517, CVSS 9.8) in Control Web Panel (< 0.9.8.1225) via the userRes POST parameter can allow attackers to run arbitrary SQL as the MySQL root user and use INTO DUMPFILE to drop a PHP webshell (leading to remote code execution). A public proof-of-concept is available, administrators should upgrade to 0.9.8.1225 immediately, audit Roundcube logs for unexpected files, and apply network restrictions while no active exploitation has been confirmed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.