Cross-Site Request Forgery Flaw in CyberPanel Affects User Credentials
CVE-2019-13056

8.8HIGH

Key Information:

Vendor
Cyberpanel
Vendor
CVE Published:
2 July 2019

Summary

A vulnerability was identified in CyberPanel up to version 1.8.4, where the lack of adequate CSRF protection on the user edit page enables an attacker to change the administrator's email and password, potentially compromising account security. This flaw underscores the importance of implementing robust CSRF defenses to protect sensitive user information and maintain system integrity.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.