PT-2019-14030 · Centos · Centos Web Panel

Published

2019-12-17

·

Updated

2023-01-24

·

CVE-2019-15235

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions CentOS Web Panel version 0.9.8.864
Description The issue allows an attacker to obtain a victim's session file name from /home/[USERNAME]/tmp/session/sess xxxxxx and the victim's token value from /usr/local/cwpsrv/logs/access log. With this information, the attacker can gain access to the victim's password for both the operating system and phpMyAdmin through an attacker's account.
Recommendations For version 0.9.8.864, consider restricting access to the /home/[USERNAME]/tmp/session/ directory and the /usr/local/cwpsrv/logs/access log file to prevent unauthorized access to session and log data. As a temporary workaround, restrict the use of the sess xxxxxx session files until a patch is available.

Exploit

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

CVE-2019-15235

Affected Products

Centos Web Panel