4
CVSSv2

CVE-2019-14246

Published: 21/08/2019 Updated: 03/03/2023
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an malicious user to discover phpMyAdmin passwords (of any user in /etc/passwd) via an attacker account.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

centos-webpanel centos web panel 0.9.8.851

Exploits

CentOS Control Web Panel (CWP) version 098851 allows an attacker to change arbitrary passwords ...