Medium severity6.1NVD Advisory· Published Jul 26, 2019· Updated Jun 17, 2026
CVE-2019-14228
CVE-2019-14228
Description
Xavier PHP Management Panel 3.0 is vulnerable to Reflected POST-based XSS via the username parameter when registering a new user at admin/includes/adminprocess.php. If there is an error when registering the user, the unsanitized username will reflect via the error page. Due to the lack of CSRF protection on the admin/includes/adminprocess.php endpoint, an attacker is able to chain the XSS with CSRF in order to cause remote exploitation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: = 3.0
- cpe:2.3:a:angry-frog:xavier:3.0:*:*:*:*:*:*:*
- Xavier/PHP Management Paneldescription
Patches
Vulnerability mechanics
References
2- m-q-t.github.io/notes/xavier-csrf-to-xss-takeover/nvdExploitThird Party Advisory
- codecanyon.net/item/xavier-php-login-script-user-management/9146226nvdProduct
News mentions
0No linked articles in our index yet.