CVE-2018-18774: XSS
Published Nov 20, 2018
·Updated
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows XSS via the admin/index.php module parameter.
Affected Software
1 affected component
Control-webpanel Webpanel<=0.9.8.740
Event History
Nov 20, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-18774?
CVE-2018-18774 is a medium severity vulnerability that allows for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2018-18774?
To fix CVE-2018-18774, upgrade your CentOS Web Panel to a version later than 0.9.8.740.
3
What is the impact of CVE-2018-18774?
The impact of CVE-2018-18774 includes the potential for attackers to execute malicious scripts in the context of the affected site.
4
Which versions of CentOS Web Panel are affected by CVE-2018-18774?
CVE-2018-18774 affects all versions of CentOS Web Panel up to and including 0.9.8.740.
5
Is there a workaround for CVE-2018-18774?
Currently, the only effective workaround for CVE-2018-18774 is to apply the necessary software updates to mitigate the vulnerability.