Public PoC Code Exposes CVSS 9.8 Control Web Panel SQL Injection CVE-2026-57517
ID: 0bdbc949-e4c1-5325-be7d-0fd29bca1a9a
STIX ID: report--0bdbc949-e4c1-5325-be7d-0fd29bca1a9a
Feed Name: securityonline.info
A critical unauthenticated blind SQL injection (CVE-2026-57517, CVSS 9.8) in Control Web Panel (< 0.9.8.1225) via the userRes POST parameter can allow attackers to run arbitrary SQL as the MySQL root user and use INTO DUMPFILE to drop a PHP webshell (leading to remote code execution). A public proof-of-concept is available, administrators should upgrade to 0.9.8.1225 immediately, audit Roundcube logs for unexpected files, and apply network restrictions while no active exploitation has been confirmed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
