CVE Feed

    Dashboard / CVE / CVE-2019-14228

    CVE-2019-14228

    Xavier PHP Management Panel 3.0 is vulnerable to Reflected POST-based XSS via the username parameter when registering a new user at admin/includes/adminprocess.php. If there is an error when registering the user, the unsanitized username will reflect via the error page. Due to the lack of CSRF protection on the admin/includes/adminprocess.php endpoint, an attacker is able to chain the XSS with CSRF in order to cause remote exploitation.

    Published:Jul 26, 2019
    Last Modified:Nov 21, 2024
    EPS:Jul 26, 2019
    EPSS Score:0.00113
    CVSS Score:6.1

    Affected Products

    Vendor
    Angry-frog
    Product
    Xavier

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High