Medium severity4.6NVD Advisory· Published Oct 31, 2019· Updated Jun 17, 2026
CVE-2019-16295
CVE-2019-16295
Description
Stored XSS in filemanager2.php in CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.885 exists via the cmd_arg parameter. This can be exploited by a local attacker who supplies a crafted filename within a directory visited by the victim.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- cpe:2.3:a:control-webpanel:webpanel:0.9.8.855:*:*:*:*:*:*:*
- CentOS-WebPanel.com/CentOS Web Paneldescription
- Range: 0.9.8.885
- Range: 0.9.8.885
Patches
Vulnerability mechanics
References
2- packetstormsecurity.com/files/154990/CWP-0.9.8.885-Cross-Site-Scripting.htmlnvdExploitThird Party AdvisoryVDB Entry
- centos-webpanel.com/changelog-cwp7nvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.