CVE-2019-15235: Medium severity centos web panel vulnerability
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.864 allows an attacker to get a victim's session file name from /home/[USERNAME]/tmp/session/sessxxxxxx, and the victim's token value from /usr/local/cwpsrv/logs/accesslog, then use them to gain access to the victim's password (for the OS and phpMyAdmin) via an attacker account. This is different from CVE-2019-14782.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-15235 vulnerability?
CVE-2019-15235 is a vulnerability in CentOS-WebPanel.com (CWP) CentOS Web Panel 0.9.8.864 that allows an attacker to access a victim's session file name and token value to gain access to the victim's password.
How severe is CVE-2019-15235?
CVE-2019-15235 has a severity level of 6.5, classified as medium.
How can an attacker exploit CVE-2019-15235?
An attacker can exploit CVE-2019-15235 by retrieving a victim's session file name and token value to gain access to the victim's password.