CVE-2019-13385: Path Traversal
Published Jul 26, 2019
·Updated
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.840, File and Directory Information Exposure in filemanager allows attackers to enumerate users and check for active users of the application by reading /tmp/login.log.
Affected Software
1 affected component
Control-webpanel Webpanel=0.9.8.840
Event History
Jul 26, 2019
CVE Published
via MITRE·12:05 PM
Data Sourced
via MITRE·12:05 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-13385?
CVE-2019-13385 is classified as a medium severity vulnerability.
2
How do I fix CVE-2019-13385?
To fix CVE-2019-13385, upgrade CentOS Web Panel to version 0.9.8.841 or later.
3
What type of vulnerability is CVE-2019-13385?
CVE-2019-13385 is a File and Directory Information Exposure vulnerability.
4
What information can be leaked due to CVE-2019-13385?
CVE-2019-13385 allows attackers to enumerate users and check for active users by accessing /tmp/login.log.
5
Which software is affected by CVE-2019-13385?
CVE-2019-13385 affects CentOS Web Panel version 0.9.8.840.