vendor:
CyberPanel
by:
Bilgi Birikim Sistemleri
8.8
CVSS
HIGH
Account Takeover
352
CWE
Product Name: CyberPanel
Affected Version From: v1.8.4
Affected Version To: v1.8.4
Patch Exists: YES
Related CWE: CVE-2019-13056
CPE: a:cyberpanel:cyberpanel
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2019
CyberPanel Administrator Account Takeover <= v1.8.4
Attacker can edit administrator's credentials like email, password. Then, access the administration panel and takeover the server. A CSRF vulnerability.
Mitigation:
Implementing CSRF protection and validating user input.