CVE-2019-16295: Control-Webpanel Webpanel
Medium severity, CVSS 4.6. EPSS: 0.5% chance of exploitation in the next 30 days.
Stored XSS in filemanager2.php in CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.885 exists via the cmd_arg parameter. This can be exploited by a local attacker who supplies a crafted filename within a directory visited by the victim.
Affected products
- Control-Webpanel Webpanel: version 0.9.8.855 only
Published 2019-10-31. Last modified 2026-06-17.