6.5
CVE-2019-14245
- EPSS 0.38%
- Veröffentlicht 21.08.2019 19:15:13
- Zuletzt bearbeitet 21.11.2024 04:26:17
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete databases (such as oauthv2) from the server via an attacker account.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Centos-webpanel ≫ Centos Web Panel Version0.9.8.851
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.38% | 0.585 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
|
| nvd@nist.gov | 5.5 | 8 | 4.9 |
AV:N/AC:L/Au:S/C:N/I:P/A:P
|
CWE-639 Authorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.