Centos control web panel 0.9.8.838 user enumeration Vulnerability / Exploit
/
/
/
Exploits / Vulnerability Discovered : 2019-07-16 |
Type : webapps |
Platform : linux
This exploit / vulnerability Centos control web panel 0.9.8.838 user enumeration is for educational purposes only and if it is used you will do on your own risk!
[+] Code ...
# Exploit Title: CWP (CentOS Control Web Panel) < 0.9.8.848 User Enumeration via HTTP Response Message
# Date: 15 July 2019
# Exploit Author: Pongtorn Angsuchotmetee, Nissana Sirijirakal, Narin Boonwasanarak
# Vendor Homepage: https://control-webpanel.com/changelog
# Software Link: Not available, user panel only available for lastest version
# Version: 0.9.8.836 to 0.9.8.847
# Tested on: CentOS 7.6.1810 (Core)
# CVE : CVE-2019-13383
# ====================================================================
# Information
# ====================================================================
Product : CWP Control Web Panel
version : 0.9.8.838
Fixed on : 0.9.8.848
Test on : CentOS 7.6.1810 (Core)
Reference : https://control-webpanel.com/
CVE-Number : 2019-13383
# ====================================================================
# Root course of the vulnerability
# ====================================================================
The server response different message between login with valid and invalid user.
This allows attackers to check whether a username is valid by reading the HTTP response.
# ====================================================================
# Steps to Reproduce
# ====================================================================
1. Login with a random user by using invalid password
# ====================================================================
# Timeline
# ====================================================================
2019-07-06: Discovered the bug
2019-07-06: Reported to vendor
2019-07-06: Vender accepted the vulnerability
2019-07-11: The vulnerability has been fixed
2019-07-15: Published