vendor:
CWP Control Web Panel
by:
Pongtorn Angsuchotmetee, Nissana Sirijirakal, Narin Boonwasanarak
7.5
CVSS
HIGH
Root Privilege Escalation
CWE
Product Name: CWP Control Web Panel
Affected Version From: 0.9.8.836
Affected Version To: 0.9.8.839
Patch Exists: YES
Related CWE: CVE-2019-13359
CPE:
Platforms Tested: CentOS 7.6.1810 (Core)
2019
CWP Control Web Panel 0.9.8.836 – 0.9.8.839 Root Privilege Escalation
The CWP Control Web Panel version 0.9.8.836 to 0.9.8.839 is vulnerable to root privilege escalation. The vulnerability occurs due to the session file being stored in the /tmp directory and the rkey value in the session file not changing when accessed by the same source IP address.
Mitigation:
Upgrade to version 0.9.8.840 or later. Ensure proper session management and secure storage of session files.