Improper access control in wpCentral - CVE-2020-9043

 

Improper access control in wpCentral - CVE-2020-9043

Published: February 18, 2020


Vulnerability identifier: #VU25411
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/U:Amber
CVE-ID: CVE-2020-9043
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Softaculous Ltd.
Affected software:
wpCentral

Detailed vulnerability description

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions in place to protect the connection key as it was displayed in the "admin_footer" in a modal dialog. A remote authenticated attacker can bypass implemented security restrictions and gain administrator access to the application.


How to mitigate CVE-2020-9043

Install updates from vendor's website.

Sources