Back to search
CVE-2019-10893
Published: Apr 18, 2019
Modified: Aug 4, 2024
PUBLISHED
Description
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version) and 0.9.8.753 (Pro) is vulnerable to Stored/Persistent XSS for Admin Email fields on the "CWP Settings > "Edit Settings" screen. By changing the email ID to any XSS Payload and clicking on Save Changes, the XSS Payload will execute.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://forum.centos-webpanel.com/informations/
x_refsource_MISC
46669
exploit
x_refsource_EXPLOIT-DB
108035
vdb-entry
x_refsource_BID
46669
exploit
x_refsource_EXPLOIT-DB
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now