CVE-2019-14245

MEDIUM

CentOS Web Panel <0.9.8.851 - Info Disclosure

Title source: llm
STIX 2.1

Description

In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete databases (such as oauthv2) from the server via an attacker account.

Scores

CVSS v3 6.5
EPSS 0.0186
EPSS Percentile 76.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-639
Status published
Products (1)
centos-webpanel/centos_web_panel 0.9.8.851
Published Aug 21, 2019
Tracked Since Feb 18, 2026