PoC Index

CVE-2019-14245

MEDIUM 6.5EPSS 1.9%

In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete databases (such as oauthv2) from the server via an attacker account.

CVSS v3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS v2.0
5.5 MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:P
EPSS
1.86% chance of exploitation in the next 30 days, 78th percentile
Published
2019-08-21
Updated
2024-08-05

Proof-of-concept exploits (3)

References

Related