packetstormsecurity.com
http://packetstormsecurity.com/files/151630/CentOS-Web-Panel-0.9.8.763-Cross-Site-Scripting.html CVE-2019-7646
MEDIUM
CentOS Web Panel 0.9.8.763 - Persistent Cross-Site Scripting
Record summary
CVE-2019-7646 has a selected CVSS score of 4.8 (medium); EIP currently links 1 catalogued exploit.
Description
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.763 is vulnerable to Stored/Persistent XSS for the "Package Name" field via the add_package module parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBCentOS Web Panel 0.9.8.763 - Persistent Cross-Site ScriptingExploitDB exploitby DKMNot analyzed1 file
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-7646 dineshmohanty.com
https://www.dineshmohanty.com/centos-web-panel-xss 46349exploit
https://www.exploit-db.com/exploits/46349