CVE-2019-13386 describes a critical vulnerability in CentOS Web Panel (CWP) version 0.9.8.846, where a hidden feature in filemanager2.php allows for arbitrary shell command execution. This flaw carries a high CVSS score of 8.8, indicating a severe risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While the vulnerability is not listed on the CISA KEV catalog and lacks public exploit intelligence such as Metasploit modules or ExploitDB entries, its high FAUCET Risk Score of 70/100 suggests significant potential for exploitation. There is currently no evidence of active exploitation or community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.9.8.846CPE matchmatch criteria | cpe:2.3:a:centos-webpanel:centos_web_panel:0.9.8.846:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.