Vulnerabilities > CVE-2019-14245 - Authorization Bypass Through User-Controlled Key vulnerability in Centos-Webpanel Centos web Panel 0.9.8.851

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
centos-webpanel
CWE-639

Summary

In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete databases (such as oauthv2) from the server via an attacker account.

Vulnerable Configurations

Part Description Count
Application
Centos-Webpanel
1

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/154155/cwp098851-drop.txt
idPACKETSTORM:154155
last seen2019-09-07
published2019-08-20
reporterPongtorn Angsuchotmetee
sourcehttps://packetstormsecurity.com/files/154155/CentOS-WebPanel.com-Control-Web-Panel-CWP-0.9.8.851-Arbitrary-Database-Drop.html
titleCentOS-WebPanel.com Control Web Panel (CWP) 0.9.8.851 Arbitrary Database Drop