PT-2019-13305 · Centos · Centos Web Panel

Narin Boonwasanarak

+2

·

Published

2019-07-26

·

Updated

2023-02-28

·

CVE-2019-13386

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CentOS Web Panel version 0.9.8.846
Description A hidden feature in the filemanager2.php file allows attackers to execute shell commands, potentially obtaining a reverse shell with user privileges.
Recommendations For version 0.9.8.846, consider disabling access to the filemanager2.php file until a patch is available to prevent exploitation of the hidden action=9 feature.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2019-13386

Affected Products

Centos Web Panel