CVE-2018-18773: CSRF
Published Nov 20, 2018
·Updated
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=rootpwd, as demonstrated by changing the root password.
Affected Software
1 affected component
Control-webpanel Webpanel<=0.9.8.740
Event History
Nov 20, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-18773?
CVE-2018-18773 is classified as a high severity vulnerability due to its potential for unauthorized access to critical system functions.
2
How can I mitigate the risks associated with CVE-2018-18773?
To mitigate CVE-2018-18773, ensure that you upgrade to a version of CentOS Web Panel later than 0.9.8.740.
3
What versions of CWP are affected by CVE-2018-18773?
CVE-2018-18773 affects all versions of CentOS Web Panel up to and including 0.9.8.740.
4
What type of attack does CVE-2018-18773 facilitate?
CVE-2018-18773 facilitates Cross-Site Request Forgery (CSRF) attacks that can compromise the root account.
5
What actions can be taken if my system is compromised due to CVE-2018-18773?
If your system is compromised due to CVE-2018-18773, immediately change the root password and audit your system for additional unauthorized changes.