CVE-2019-7646
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 7.1%
from disclosure to weapon0 days
Published on NVDMar 26
1st PoCFeb 11
exploitation probability
7.1%top 6% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.763 is vulnerable to Stored/Persistent XSS for the "Package Name" field via the add_package module parameter.
Affected products
n/a · n/apublic PoCs found — 3
cve_referencepacketstormsecurity.com/files/151630/CentOS-Web-Panel-0.9.8.763-Cross-Site-Scripting.htmlunverifiedcve_referencewww.exploit-db.com/exploits/46349/unverifiedexploitdbwww.exploit-db.com/exploits/46349unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.