Impact
The vulnerability arises from insufficient validation in the Multilang adminbin component. An attacker can supply crafted input that bypasses validation and causes the server to execute arbitrary commands, leading to complete compromise of the affected system.
Affected Systems
The flaw affects Webpros’ WP Squared and cPanel products. No specific version information is supplied in the current data, so any installation of these products that has not applied the latest patch is potentially vulnerable. Administrators should verify that the system is running the most recent release from the vendor to ensure protection.
Risk and Exploitability
The CVSS score of 9.9 indicates a critical level of risk. No EPSS score is available, and the vulnerability is not currently listed in the CISA KEV catalogue. Attackers would most likely exploit the vulnerability by sending a specially crafted request to the Multilang adminbin endpoint, requiring no user interaction beyond access to the interface. Because it allows remote command execution, the impact is essentially total system compromise.
OpenCVE Enrichment