First published: Mon Jan 22 2018(Updated: )
index.php in CentOS-WebPanel.com (aka CWP) CentOS Web Panel through v0.9.8.12 has XSS via the id parameter to the phpini_editor module or the email_address parameter to the mail_add-new module.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CWP Control Web Panel | <=0.9.8.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-5962 is classified as a medium severity vulnerability due to the potential for XSS attacks.
To address CVE-2018-5962, update the CentOS Web Panel to a version later than 0.9.8.12, which has patched this vulnerability.
CVE-2018-5962 allows an attacker to inject malicious scripts through the id parameter or email_address parameter causing XSS issues.
CVE-2018-5962 affects all versions of CentOS Web Panel up to and including 0.9.8.12.
Yes, CVE-2018-5962 can be easily exploited by sending crafted requests to vulnerable parameters in the CentOS Web Panel.