Description
The FileManager in InfinitumIT DirectAdmin through v1.561 has XSS via CMD_FILE_MANAGER, CMD_SHOW_USER, and CMD_SHOW_RESELLER; an attacker can bypass the CSRF protection with this, and take over the administration panel.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-2897 | The FileManager in InfinitumIT DirectAdmin through v1.561 has XSS via CMD_FILE_MANAGER, CMD_SHOW_USER, and CMD_SHOW_RESELLER; an attacker can bypass the CSRF protection with this, and take over the administration panel. |
References
History
Tue, 16 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Directadmin
Directadmin directadmin |
|
| CPEs | cpe:2.3:a:directadmin:directadmin:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Infinitumit
Infinitumit directadmin |
Directadmin
Directadmin directadmin |
| Metrics |
cvssV3_0
|
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T22:48:08.994Z
Reserved: 2019-04-11T00:00:00.000Z
Link: CVE-2019-11193
No data.
Status : Analyzed
Published: 2019-04-30T19:29:03.813
Modified: 2025-12-16T21:13:40.773
Link: CVE-2019-11193
No data.
OpenCVE Enrichment
No data.
EUVD