First published: Tue Mar 26 2019(Updated: )
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.763 is vulnerable to Stored/Persistent XSS for the "Package Name" field via the add_package module parameter.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CWP Control Web Panel | <=0.9.8.763 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-7646 is classified as a medium severity XSS vulnerability.
To fix CVE-2019-7646, update your CentOS Web Panel to a version later than 0.9.8.763.
CVE-2019-7646 allows attackers to execute arbitrary JavaScript in the context of users visiting the affected web panel.
CVE-2019-7646 affects CentOS Web Panel versions up to and including 0.9.8.763.
You can identify CVE-2019-7646 by testing the 'Package Name' field in the add_package module for potential XSS payload execution.