clonos.php in ClonOS WEB control panel 19.09 allows remote attackers to gain full access via change password requests because there is no session management.
References
Configurations
History
21 Nov 2024, 04:33
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/154986/ClonOs-WEB-UI-19.09-Improper-Access-Control.html - | |
References | () https://github.com/Andhrimnirr/ClonOS-WEB-control-panel-multi-vulnerability - Exploit, Third Party Advisory |
Information
Published : 2019-10-24 20:15
Updated : 2024-11-21 04:33
NVD link : CVE-2019-18418
Mitre link : CVE-2019-18418
CVE.ORG link : CVE-2019-18418
JSON object : View
Products Affected
clonos
- clonos
CWE
CWE-384
Session Fixation