CVE-2019-11193: XSS
Published Apr 30, 2019
·Updated
The FileManager in InfinitumIT DirectAdmin through v1.561 has XSS via CMDFILEMANAGER, CMDSHOWUSER, and CMDSHOWRESELLER; an attacker can bypass the CSRF protection with this, and take over the administration panel.
Affected Software
2 affected components
InfinitumIT DirectAdmin<=1.561
DirectAdmin DirectAdmin<=1.561
Event History
Apr 30, 2019
CVE Published
via MITRE·06:36 PM
Data Sourced
via MITRE·06:36 PM
Description
Data Sourced
via NVD·07:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-11193?
CVE-2019-11193 is classified as a high severity vulnerability due to its potential for remote code execution through XSS.
2
How do I fix CVE-2019-11193?
To fix CVE-2019-11193, update DirectAdmin to version 1.562 or later, which addresses the XSS vulnerability.
3
What type of vulnerability is CVE-2019-11193?
CVE-2019-11193 is an XSS (Cross-Site Scripting) vulnerability affecting the FileManager in DirectAdmin.
4
Can CVE-2019-11193 lead to unauthorized access?
Yes, CVE-2019-11193 can allow attackers to bypass CSRF protections and potentially take over the administration panel.
5
Which versions of DirectAdmin are affected by CVE-2019-11193?
CVE-2019-11193 affects DirectAdmin versions up to and including 1.561.