CVE-2018-18324: XSS
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has XSS via the admin/fileManager2.php fmcurrentdir parameter, or the admin/index.php module, servicestart, servicefullstatus, servicerestart, servicestop, or file (within the fileeditor) parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-18324?
CVE-2018-18324 has a high severity due to the potential exploitation through cross-site scripting (XSS).
How do I fix CVE-2018-18324?
To fix CVE-2018-18324, update CentOS Web Panel to a version that addresses this vulnerability, preferably later than 0.9.8.480.
What types of attacks can CVE-2018-18324 enable?
CVE-2018-18324 can enable cross-site scripting attacks, which may lead to session hijacking or unauthorized access.
Is CVE-2018-18324 specific to certain parameters?
Yes, CVE-2018-18324 is specifically related to the fm_current_dir parameter in admin/fileManager2.php and several parameters in admin/index.php.
Who is affected by CVE-2018-18324?
CVE-2018-18324 affects users of CentOS Web Panel version 0.9.8.480.