@murad99
Is there a reason you are still running CentOS 7, a past EOL OS?
That alone is a massive security hole.
The past several weeks they have been Kernel updates almost every other day, at least for AL9 and AL10.
But to close some of the security holes, I would updated your:
Base PHP to at least 8.3.33 and the PHP-FPM for the websites. (I'm glad CWP finally got PHP updated)
Apache is at 2.4.68
Nginx is at 1.30.4
jQuery has several notable past Common Vulnerabilities and Exposures (CVEs) related to Cross-Site Scripting (XSS) and DOM manipulation.
(There are 137 entries just for jQuery)
That's not counting the CVE's for CentOS 7, Apache <2.4.68, Nginx <1.30 and PHP <8.3.33
Our AlmaLinux 9 servers are all OK.
But we try to keep everything updated on the server side, unfortunately that doesn't work with some users. :/
As I mentioned at the beginning of this thread, I observed the same issue on
two different CWP servers, and one of those servers was running
AlmaLinux 9.
I agree that the older versions on my CentOS 7 server are my responsibility, and I am not trying to argue otherwise. However, I want to emphasize that I also found the same injected jQuery files on an
AlmaLinux 9 server.
I am not particularly concerned about my own server in this case; I decided to report the issue publicly because I believe there may be something worth investigating.
I have shared what I found. The interpretation and conclusion are ultimately up to the CWP team and the community.
One more thing I would like to mention: it appears that registering on the forum with a
Gmail address is currently not working, as the confirmation email does not arrive. This may give the impression that forum registration is disabled. There may be other users experiencing the same issue who are currently unable to report their findings or ask for help here.
I thought it was worth mentioning this as well.