CVE-2019-13359: Malicious File Upload
Published Jul 16, 2019
·Updated
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, a cwpsrv-xxx cookie allows a normal user to craft and upload a session file to the /tmp directory, and use it to become the root user.
Affected Software
1 affected component
Control-webpanel Webpanel=0.9.8.836
Event History
Jul 16, 2019
CVE Published
via MITRE·05:02 PM
Data Sourced
via MITRE·05:02 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-13359?
CVE-2019-13359 is considered a high severity vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2019-13359?
To fix CVE-2019-13359, update your CentOS Web Panel to the latest version provided by the vendor.
3
Who is affected by CVE-2019-13359?
CVE-2019-13359 affects users of CentOS Web Panel version 0.9.8.836.
4
What type of vulnerability is CVE-2019-13359?
CVE-2019-13359 is a privilege escalation vulnerability that allows normal users to gain root access.
5
What should I do if I cannot patch CVE-2019-13359 immediately?
If immediate patching is not possible for CVE-2019-13359, consider restricting user access and monitoring server logs for suspicious activity.