CVE-2019-13605: High severity centos web panel vulnerability
Published Jul 16, 2019
·Updated
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.838 to 0.9.8.846, remote attackers can bypass authentication in the login process by leveraging the knowledge of a valid username. The attacker must defeat an encoding that is not equivalent to base64, and thus this is different from CVE-2019-13360.
Affected Software
1 affected component
Control-webpanel Webpanel=0.9.8.836
Event History
Jul 16, 2019
CVE Published
via MITRE·04:46 PM
Data Sourced
via MITRE·04:46 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-13605?
CVE-2019-13605 has been classified as a medium severity vulnerability due to its potential for remote authentication bypass.
2
How do I fix CVE-2019-13605?
To fix CVE-2019-13605, update CentOS Web Panel to a version later than 0.9.8.846.
3
Who is affected by CVE-2019-13605?
CVE-2019-13605 affects users of CentOS Web Panel versions between 0.9.8.838 and 0.9.8.846.
4
Can CVE-2019-13605 be exploited remotely?
Yes, CVE-2019-13605 can be exploited remotely if an attacker knows a valid username.
5
What type of vulnerability is CVE-2019-13605?
CVE-2019-13605 is an authentication bypass vulnerability.