Stored XSS Vulnerability in CentOS Web Panel by CentOS
CVE-2019-10261
4.8MEDIUM
What is CVE-2019-10261?
The CentOS Web Panel (CWP) version 0.9.8.789 contains a vulnerability that allows for Stored or Persistent Cross-Site Scripting (XSS) in the 'Name Server 1' and 'Name Server 2' fields. This issue arises from improper handling of input when editing nameserver IP addresses through the DNS Functions interface. An attacker can exploit this vulnerability to inject malicious scripts that are then stored and executed in the context of user sessions, potentially compromising sensitive user data and session information.
