#VU35656 Information disclosure in CentOS Web Panel - CVE-2019-13385
Published: July 26, 2019 / Updated: August 8, 2020
CentOS Web Panel
CentOS Web Panel
Description
The vulnerability allows a remote authenticated user to gain access to sensitive information.
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.840, File and Directory Information Exposure in filemanager allows attackers to enumerate users and check for active users of the application by reading /tmp/login.log.