CVE-2019-13476: XSS
Published Aug 21, 2019
·Updated
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.837, XSS in the domain parameter allows a low-privilege user to achieve root access via the email list page.
Affected Software
1 affected component
Control-webpanel Webpanel=0.9.8.837
Event History
Aug 21, 2019
CVE Published
via MITRE·07:02 PM
Data Sourced
via MITRE·07:02 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-13476?
CVE-2019-13476 is considered a high severity vulnerability due to the potential for root access exploitation.
2
How do I fix CVE-2019-13476?
To fix CVE-2019-13476, upgrade to a patched version of CentOS Web Panel above 0.9.8.837.
3
Who is affected by CVE-2019-13476?
CVE-2019-13476 affects users of CentOS Web Panel version 0.9.8.837.
4
What is the nature of CVE-2019-13476?
CVE-2019-13476 is a Cross-Site Scripting (XSS) vulnerability that allows unauthorized actions.
5
Can low-privilege users exploit CVE-2019-13476?
Yes, low-privilege users can exploit CVE-2019-13476 to gain root access through the email list page.