CVE-2019-7646: XSS
Published Mar 26, 2019
·Updated
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.763 is vulnerable to Stored/Persistent XSS for the "Package Name" field via the addpackage module parameter.
Affected Software
1 affected component
Control-webpanel Webpanel<=0.9.8.763
Event History
Mar 26, 2019
CVE Published
via MITRE·03:02 PM
Data Sourced
via MITRE·03:02 PM
Description
Data Sourced
via NVD·04:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-7646?
CVE-2019-7646 is classified as a medium severity XSS vulnerability.
2
How do I fix CVE-2019-7646?
To fix CVE-2019-7646, update your CentOS Web Panel to a version later than 0.9.8.763.
3
What is the impact of CVE-2019-7646 on my system?
CVE-2019-7646 allows attackers to execute arbitrary JavaScript in the context of users visiting the affected web panel.
4
Which versions of CentOS Web Panel are affected by CVE-2019-7646?
CVE-2019-7646 affects CentOS Web Panel versions up to and including 0.9.8.763.
5
How can I identify if CVE-2019-7646 is present in my environment?
You can identify CVE-2019-7646 by testing the 'Package Name' field in the add_package module for potential XSS payload execution.