CVE-2019-13383: Medium severity centos web panel vulnerability
Published Jul 16, 2019
·Updated
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, the Login process allows attackers to check whether a username is valid by reading the HTTP response.
Affected Software
1 affected component
Control-webpanel Webpanel=0.9.8.836
Event History
Jul 16, 2019
CVE Published
via MITRE·04:54 PM
Data Sourced
via MITRE·04:54 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-13383?
CVE-2019-13383 is classified as a medium severity vulnerability due to its ability to enable user enumeration attacks.
2
How do I fix CVE-2019-13383?
To fix CVE-2019-13383, you should upgrade to the latest version of CentOS Web Panel that addresses this vulnerability.
3
What does CVE-2019-13383 exploit?
CVE-2019-13383 exploits a flaw in the login process that allows attackers to determine valid usernames based on HTTP response messages.
4
Who is affected by CVE-2019-13383?
CVE-2019-13383 affects users of CentOS Web Panel version 0.9.8.836 and earlier.
5
What is the impact of CVE-2019-13383?
The impact of CVE-2019-13383 includes the potential for unauthorized user enumeration, which may lead to further attacks.