CVE-2019-13477: CSRF
Published Aug 21, 2019
·Updated
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.837, CSRF in the forgot password function allows an attacker to change the password for the root account.
Affected Software
1 affected component
Control-webpanel Webpanel=0.9.8.837
Event History
Aug 21, 2019
CVE Published
via MITRE·06:55 PM
Data Sourced
via MITRE·06:55 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-13477?
CVE-2019-13477 is considered a critical vulnerability due to its ability to compromise the root account via CSRF attacks.
2
How do I fix CVE-2019-13477?
To fix CVE-2019-13477, you should update CentOS Web Panel to the latest version that addresses this vulnerability.
3
What does CVE-2019-13477 allow an attacker to do?
CVE-2019-13477 allows an attacker to change the password for the root account through a CSRF exploit.
4
Which version of CentOS Web Panel is affected by CVE-2019-13477?
CVE-2019-13477 affects CentOS Web Panel version 0.9.8.837.
5
Is CVE-2019-13477 a local or remote vulnerability?
CVE-2019-13477 is a remote vulnerability as it can be exploited over the network without user interaction.