vendor:
CWP Control Web Panel
by:
Pongtorn Angsuchotmetee
8.8
CVSS
HIGH
User panel bypass Login
287, 287
CWE
Product Name: CWP Control Web Panel
Affected Version From: 0.9.8.836
Affected Version To: 0.9.8.846
Patch Exists: YES
Related CWE: CVE-2019-13360, CVE-2019-13605
CPE: a:centos_web_panel:centos_web_panel
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: CentOS 7.6.1810 (Core)
2019
CWP (CentOS Control Web Panel) < 0.9.8.847 Bypass Login
After login success, the application will retuens base64 value and use it to authenticate again, That allow attacker to modify the response and become a user. For version 0.9.8.836 to 0.9.8.837, the response format is <username>||/<username>/theme/original and for version 0.9.8.838 to 0.9.8.846, the response format is username||/<username>/theme/original.
Mitigation:
Upgrade to version 0.9.8.848 or later