Medium severity6.1NVD Advisory· Published Apr 30, 2019· Updated Jun 17, 2026
CVE-2019-11193
CVE-2019-11193
Description
The FileManager in InfinitumIT DirectAdmin through v1.561 has XSS via CMD_FILE_MANAGER, CMD_SHOW_USER, and CMD_SHOW_RESELLER; an attacker can bypass the CSRF protection with this, and take over the administration panel.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: <=1.561
<=1.561+ 1 more
- (no CPE)range: <=1.561
- cpe:2.3:a:directadmin:directadmin:*:*:*:*:*:*:*:*range: <=1.561
Patches
Vulnerability mechanics
References
3- packetstormsecurity.com/files/152494/DirectAdmin-1.561-Cross-Site-Scripting.htmlnvdExploitThird Party AdvisoryVDB Entry
- numanozdemir.com/respdisc/directadmin.pdfnvdBroken LinkExploitThird Party Advisory
- www.exploit-db.com/exploits/46694nvdExploitThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.