First published: Tue Nov 20 2018(Updated: )
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows XSS via the admin/index.php module parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CWP Control Web Panel | <=0.9.8.740 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-18774 is a medium severity vulnerability that allows for cross-site scripting (XSS) attacks.
To fix CVE-2018-18774, upgrade your CentOS Web Panel to a version later than 0.9.8.740.
The impact of CVE-2018-18774 includes the potential for attackers to execute malicious scripts in the context of the affected site.
CVE-2018-18774 affects all versions of CentOS Web Panel up to and including 0.9.8.740.
Currently, the only effective workaround for CVE-2018-18774 is to apply the necessary software updates to mitigate the vulnerability.