8.8
CVSSv3

CVE-2019-13605

Published: 16/07/2019 Updated: 24/01/2023
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.838 to 0.9.8.846, remote attackers can bypass authentication in the login process by leveraging the knowledge of a valid username. The attacker must defeat an encoding that is not equivalent to base64, and thus this is different from CVE-2019-13360.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

control-webpanel webpanel 0.9.8.836

Exploits

# Exploit Title: CWP (CentOS Control Web Panel) < 098847 Bypass Login # Date: 6 July 2019 # Exploit Author: Pongtorn Angsuchotmetee # Vendor Homepage: control-webpanelcom/changelog # Software Link: Not available, user panel only available for latest version # Version: 098836 to 098846 # Tested on: CentOS 761810 (Core) # CVE : ...
CentOS Control Web Panel version 098836 suffers from an authentication bypass vulnerability ...