PT-2019-4355 · Centos · Centos Web Panel

Pongtorn Angsuchotmetee

·

Published

2019-07-15

·

Updated

2023-01-24

·

CVE-2019-13360

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CentOS Web Panel version 0.9.8.836
Description The issue is related to weaknesses in the authentication procedure of the CentOS Web Panel application. It allows a remote attacker to bypass authentication in the login process by leveraging knowledge of a valid username. This can potentially enable the attacker to elevate their privileges.
Recommendations For version 0.9.8.836, consider restricting access to the login process until a patch is available. As a temporary workaround, monitor login attempts closely to detect potential unauthorized access.

Exploit

Fix

Improper Authentication

IDOR

Weakness Enumeration

Related Identifiers

BDU:2020-00076
CVE-2019-13360

Affected Products

Centos Web Panel