CVE-2019-14246: Medium severity centos web panel vulnerability
Published Aug 21, 2019
·Updated
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to discover phpMyAdmin passwords (of any user in /etc/passwd) via an attacker account.
Affected Software
1 affected component
CentOS-WebPanel CentOS Web Panel=0.9.8.851
Event History
Aug 21, 2019
CVE Published
via MITRE·06:38 PM
Data Sourced
via MITRE·06:38 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-14246?
CVE-2019-14246 has a critical severity rating as it allows unauthorized access to sensitive information.
2
How do I fix CVE-2019-14246?
To fix CVE-2019-14246, update CentOS Web Panel to the latest version that addresses this vulnerability.
3
What is affected by CVE-2019-14246?
CVE-2019-14246 specifically affects CentOS Web Panel version 0.9.8.851.
4
What kind of information can be compromised by CVE-2019-14246?
CVE-2019-14246 allows attackers to discover phpMyAdmin passwords for any user listed in the /etc/passwd file.
5
Who is at risk from CVE-2019-14246?
Users and administrators of CentOS Web Panel version 0.9.8.851 are at risk if they do not apply the necessary update.