Your post makes no sense.All you have done is link to many RCE vulnerabilities in different applications - some dated 16 years ago. What have that to do with anything?
No one is saying that RCE is a "new thing"... is a security issue, and yes, if has happend before in different aplications... but what have that to do with the LACK OF COMMUNICATION from CWP, about the RCE issue that happend in the control panel.
Those links have nothing to do with the CWP situation.
Or are you stating that just because RCE is a thing, CWP shouldn't be blamed because of it?
For that logic, every attack, malware or exploit have a excuse: "oh well, it happend to others, so..."
Do you see the fault in your logic?
The point here is that
CWP did NOT acknowledge the security issue, not even a post to alert the administrators about it. Not even in the post that was created
by a forum member to alert.
Can you provide some way in HOW they confirm the issue?
So yes, CWP is to blame. They fixed, but silent fix a security issue is NOT the way that any credible company does this - and you should know that!
And about the other issue, @Starburst, you can be whatever you want to be. You can be a CWP partner... but you ARE NOT CWP.
Again, you are making no sense... How i was spreading misinformation?
- You are just a forum member? Yes
- You provided false information about in how CWP had nothing to do with a security issue in they panel? Yes
- You are trying to prove that just because RCE exploits exist - had had FOR YEARS - that somehow make CWP team not responsible to disclose a security issue in they panel? Yes.
- You are a CWP Partner? Yes
- You are NOT a CWP team member, so you cannot talk for them? Yes
Is anything here wrong?
In fact, your response about all this is troubling, because you cannot call you a sys admin and state that every exploit in a software should be "excused" just because "it exist"... That is NOT how this works...
You are a forum member, that's it. You are not the entity responsible for the CWP development, and you don't have any say or do in how CWP is developed. Only the CWP team has, and to this point, no one is talking anything.
at best yes, you are a CWP partner... but STILL NOT A DEVELOPER of the CWP team.