CVE-2022-25047: Medium severity centos web panel vulnerability
Published Jul 7, 2022
·Updated
The password reset token in CWP v0.9.8.1126 is generated using known or predictable values.
Affected Software
1 affected component
Control-webpanel Webpanel=0.9.8.1126
Event History
Jul 7, 2022
CVE Published
via MITRE·11:29 AM
Data Sourced
via MITRE·11:29 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-25047?
CVE-2022-25047 has been classified as a medium severity vulnerability.
2
How does CVE-2022-25047 affect users of CWP v0.9.8.1126?
CVE-2022-25047 allows attackers to potentially predict valid password reset tokens, compromising user accounts.
3
How do I fix CVE-2022-25047?
To mitigate CVE-2022-25047, update to a later version of Control Web Panel that addresses this vulnerability.
4
What versions of Control Web Panel are affected by CVE-2022-25047?
CVE-2022-25047 specifically affects Control Web Panel version 0.9.8.1126.
5
What actions should I take if I am using CWP v0.9.8.1126?
If you are using CWP v0.9.8.1126, it is recommended to immediately update to the latest version to secure your installation against CVE-2022-25047.