First published: Fri Jul 26 2019(Updated: )
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, Reflected XSS in filemanager2.php (parameter fm_current_dir) allows attackers to steal a cookie or session, or redirect to a phishing website.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CWP Control Web Panel | =0.9.8.846 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.