CVE-2020-15624: (0Day) CentOS Web Panel ajax_new_account domain SQL Injection Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajaxnewaccount.php. When parsing the domain parameter, the process does not properly validate a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to disclose information in the context of root. Was ZDI-CAN-9727.
Other sources
This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajaxnewaccount.php. When parsing the domain parameter, the process does not properly validate a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to disclose information in the context of root.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-15624?
CVE-2020-15624 has a moderate severity rating due to its ability to allow remote information disclosure without authentication.
How do I fix CVE-2020-15624?
To fix CVE-2020-15624, it is recommended to upgrade to the latest version of CentOS Web Panel that addresses this vulnerability.
What versions are affected by CVE-2020-15624?
CVE-2020-15624 affects CentOS Web Panel version 0.9.8.923.
Can CVE-2020-15624 be exploited without authentication?
Yes, CVE-2020-15624 can be exploited without authentication, allowing remote attackers to access sensitive information.
What impact does CVE-2020-15624 have on systems?
The impact of CVE-2020-15624 includes the potential unauthorized disclosure of sensitive information from the affected CentOS Web Panel installations.