PT-2020-14542 · Centos · Centos Web Panel

Caspertea

+1

·

Published

2020-06-25

·

Updated

2023-01-24

·

CVE-2020-15619

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions CentOS Web Panel version cwp-e17.0.9.8.923
Description This issue allows remote attackers to disclose sensitive information without requiring authentication. The flaw exists in the ajax list accounts.php file, specifically when parsing the type parameter, which does not properly validate user-supplied strings before using them to construct SQL queries. This can be leveraged to disclose information in the context of root.
Recommendations For CentOS Web Panel version cwp-e17.0.9.8.923, consider restricting access to the ajax list accounts.php file until a patch is available. As a temporary workaround, avoid using the type parameter in the affected API endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2020-15619
ZDI-20-766

Affected Products

Centos Web Panel