PT-2019-15401 · Clonos · Clonos Web Control Panel

Published

2019-10-24

·

Updated

2019-10-29

·

CVE-2019-18418

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ClonOS WEB control panel version 19.09
Description The issue allows remote attackers to gain full access via change password requests due to the lack of session management in the clonos.php file.
Recommendations For ClonOS WEB control panel version 19.09, consider implementing proper session management to prevent unauthorized access. As a temporary workaround, restrict access to the clonos.php file until a patch is available.

Exploit

Fix

Session Fixation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-18418

Affected Products

Clonos Web Control Panel