Stored XSS Vulnerability in CentOS Web Panel by CentOS
CVE-2019-10261

4.8MEDIUM

Key Information:

Vendor
CVE Published:
3 April 2019

What is CVE-2019-10261?

The CentOS Web Panel (CWP) version 0.9.8.789 contains a vulnerability that allows for Stored or Persistent Cross-Site Scripting (XSS) in the 'Name Server 1' and 'Name Server 2' fields. This issue arises from improper handling of input when editing nameserver IP addresses through the DNS Functions interface. An attacker can exploit this vulnerability to inject malicious scripts that are then stored and executed in the context of user sessions, potentially compromising sensitive user data and session information.

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2019-10261 : Stored XSS Vulnerability in CentOS Web Panel by CentOS