Categories: Security News

Multiple Persistent XSS vulnerabilities in CentOS Web Panel

CentOS Web Panel is a Linux based web panel like Cpanel or Plesk and it has a couple of features for server management.

A Client-Side XSS vulnerability detected with CentOS Web Panel Version 0.9.8.12, allows an attacker to inject remote codes into the client-side browser to application requests.

With XSS vulnerability attacker can inject untrusted snippets of JavaScript into your application without validation. This JavaScript is then executed by the victim who is visiting the target site.

The vulnerabilities are located in the `id` and `email_address` parameters of the `index.php` file POST method request. Remote attackers are able to inject script code to the POST method request to manipulate the item listing output context. The request method to inject is POST and the attack vector is persistent on the application-side. The injection points are the both add POST method requests and the execution point occurs in the output location of both modules.

Security Researchers from vulnerability laboratory detected the vulnerability, it allows an attacker to hijack the sessions, Phishing attacks, malicious external redirects.

Also Read All Versions of ASUS Routers Affected by Multiple Vulnerabilities that Allows to Gain Complete Router Access

The vulnerability is categorized as a medium one and the exploitation requires no privileged web-application user account and low user interaction. Researchers published a PoC explaining the vulnerability.

Mitigations – CentOS Web Panel

  • Researchers suggested sanitizing in the vulnerable `id` and `email address` parameters of the index.php file.
  • Disallow special characters and parameter inputs.
Gurubaran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

New WordPress Plugin That Weaponizes Legit Sites To Steal Customer Payment Data

Cybercriminals have developed PhishWP, a malicious WordPress plugin, to facilitate sophisticated phishing attacks, which enable…

2 hours ago

New FireScam Android Malware Abusing Firebase Services To Evade Detection

FireScam is multi-stage malware disguised as a fake “Telegram Premium” app that steals data and…

4 hours ago

Hackers Weaponize Security Testing By Weaponizing npm, PyPI, & Ruby Exploit Packages

Over the past year, malicious actors have been abusing OAST services for data exfiltration, C2…

4 hours ago

Hackers Mimic Social Security Administration To Deliver ConnectWise RAT

A phishing campaign spoofing the United States Social Security Administration emerged in September 2024, delivering…

5 hours ago

EAGERBEE Malware Updated It’s Arsenal With Payloads & Command Shells

The Kaspersky researchers investigation into the EAGERBEE backdoor revealed its deployment within Middle Eastern ISPs…

5 hours ago

CyTwist Launches Advanced Security Solution to Identify AI-Driven Cyber Threats in Minutes

CyTwist, a leader in advanced next-generation threat detection solutions, has launched its patented detection engine…

6 hours ago