CVE-2019-16295: XSS
Published Oct 31, 2019
·Updated
Stored XSS in filemanager2.php in CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.885 exists via the cmdarg parameter. This can be exploited by a local attacker who supplies a crafted filename within a directory visited by the victim.
Affected Software
1 affected component
Control-webpanel Webpanel=0.9.8.855
Event History
Oct 31, 2019
CVE Published
via MITRE·08:59 PM
Data Sourced
via MITRE·08:59 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-16295.
2
What is the title of this vulnerability?
The title of this vulnerability is 'Stored XSS in filemanager2.php in CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.885 exists vi...'.
3
What is the severity of CVE-2019-16295?
The severity of CVE-2019-16295 is medium with a severity value of 4.6.
4
What is the affected software for CVE-2019-16295?
The affected software for CVE-2019-16295 is Control-webpanel Webpanel version 0.9.8.855.
5
How can this vulnerability be exploited?
This vulnerability can be exploited by a local attacker who supplies a crafted filename within a directory visited by the victim.