CVE-2019-13385

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
26/07/2019
Last modified:
24/01/2023

Description

In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.840, File and Directory Information Exposure in filemanager allows attackers to enumerate users and check for active users of the application by reading /tmp/login.log.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:control-webpanel:webpanel:0.9.8.840:*:*:*:*:*:*:*