CVE-2019-13387: XSS
Published Jul 26, 2019
·Updated
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, Reflected XSS in filemanager2.php (parameter fmcurrentdir) allows attackers to steal a cookie or session, or redirect to a phishing website.
Affected Software
1 affected component
Control-webpanel Webpanel=0.9.8.846
Event History
Jul 26, 2019
CVE Published
via MITRE·12:06 PM
Data Sourced
via MITRE·12:06 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-13387?
CVE-2019-13387 is considered a medium severity vulnerability due to its potential impact on user sessions.
2
How does CVE-2019-13387 work?
CVE-2019-13387 exploits reflected XSS in the filemanager2.php script, allowing attackers to manipulate user sessions.
3
How do I fix CVE-2019-13387?
To fix CVE-2019-13387, upgrade to a patched version of CentOS Web Panel that addresses the reflected XSS issue.
4
Who is affected by CVE-2019-13387?
CVE-2019-13387 affects users of CentOS Web Panel version 0.9.8.846.
5
What can attackers do with CVE-2019-13387?
Attackers leveraging CVE-2019-13387 can steal cookies, hijack user sessions, or redirect users to phishing sites.