CVE-2018-5962: XSS
index.php in CentOS-WebPanel.com (aka CWP) CentOS Web Panel through v0.9.8.12 has XSS via the id parameter to the phpinieditor module or the emailaddress parameter to the mailadd-new module.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-5962?
CVE-2018-5962 is classified as a medium severity vulnerability due to the potential for XSS attacks.
How do I fix CVE-2018-5962?
To address CVE-2018-5962, update the CentOS Web Panel to a version later than 0.9.8.12, which has patched this vulnerability.
What impact does CVE-2018-5962 have on my CentOS Web Panel?
CVE-2018-5962 allows an attacker to inject malicious scripts through the id parameter or email_address parameter causing XSS issues.
Which versions of CentOS Web Panel are affected by CVE-2018-5962?
CVE-2018-5962 affects all versions of CentOS Web Panel up to and including 0.9.8.12.
Is CVE-2018-5962 easy to exploit?
Yes, CVE-2018-5962 can be easily exploited by sending crafted requests to vulnerable parameters in the CentOS Web Panel.