vendor:
CWP Control Web Panel
by:
Pongtorn Angsuchotmetee, Nissana Sirijirakal, Narin Boonwasanarak
5.3
CVSS
MEDIUM
User Enumeration
200
CWE
Product Name: CWP Control Web Panel
Affected Version From: 0.9.8.836
Affected Version To: 0.9.8.847
Patch Exists: YES
Related CWE: CVE-2019-13383
CPE: a:control_web_panel:cwp_control_web_panel
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: CentOS 7.6.1810 (Core)
2019
CWP (CentOS Control Web Panel) < 0.9.8.848 User Enumeration via HTTP Response Message
The server response different message between login with valid and invalid user. This allows attackers to check whether a username is valid by reading the HTTP response.
Mitigation:
Upgrade to version 0.9.8.848 or later