Permissions, Privileges, and Access Controls in CentOS Web Panel - CVE-2019-14245

 

Permissions, Privileges, and Access Controls in CentOS Web Panel - CVE-2019-14245

Published: August 21, 2019 / Updated: August 8, 2020


Vulnerability identifier: #VU35600
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-14245
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to manipulate data.

In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete databases (such as oauthv2) from the server via an attacker account.


Affected software

CentOS Web Panel

How to mitigate CVE-2019-14245

Install update from vendor's website.


External References

Related Security Bulletins