435
VMScore

CVE-2018-18774

Published: 20/11/2018 Updated: 24/01/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

CentOS-WebPanel.com (aka CWP) CentOS Web Panel up to and including 0.9.8.740 allows XSS via the admin/index.php module parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

control-webpanel webpanel

Exploits

# Title: CentOS Web Panel Root Account Takeover + Remote Command Execution <= v098740 # Author: InfinitumIT (infinitumitcomtr) # Vendor Homepage: centos-webpanelcom # Software Link: centos-webpanelcom/cwp-latest # Version: Up to v098740 # CVE: CVE-2018-18773, CVE-2018-18772 and CVE-2018-18774 #? Detailed: numan ...
CentOS Web Panel versions 098740 and below suffer from cross site request forgery and cross site scripting vulnerabilities that can be leveraged to achieve remote root command execution ...