Exploitation Summary
EIP tracks 1 public exploit for CVE-2019-7646. PoCs published by DKM.
AI-analyzed exploit summary This is a writeup describing a stored XSS vulnerability in CentOS Web Panel 0.9.8.763, where the 'Package Name' field in the 'Add a Package' module fails to sanitize user input. The steps to reproduce involve injecting a simple JavaScript payload, which executes when listing packages.
Description
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.763 is vulnerable to Stored/Persistent XSS for the "Package Name" field via the add_package module parameter.
Exploits (1)
This is a writeup describing a stored XSS vulnerability in CentOS Web Panel 0.9.8.763, where the 'Package Name' field in the 'Add a Package' module fails to sanitize user input. The steps to reproduce involve injecting a simple JavaScript payload, which executes when listing packages.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N