PT-2019-4355 · Centos · Centos Web Panel

·

CVE-2019-13360

·

Published

2019-07-15

·

Updated

2023-01-24

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CentOS Web Panel version 0.9.8.836
Description The issue is related to weaknesses in the authentication procedure of the CentOS Web Panel application. It allows a remote attacker to bypass authentication in the login process by leveraging knowledge of a valid username. This can potentially enable the attacker to elevate their privileges.
Recommendations For version 0.9.8.836, consider restricting access to the login process until a patch is available. As a temporary workaround, monitor login attempts closely to detect potential unauthorized access.

Exploit

Fix

Improper Authentication

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00076
CVE-2019-13360

Affected Products

Centos Web Panel