CentOS Web Panel Root Account Takeover + Remote Command Execution <= v0.9.8.740
Attackers can change target server's root password and execute command, by CSRF vulnerability. Also, there is a XSS vulnerability, hacker can exploit the CSRF vulnerability by this XSS vulnerability and run bad-purposed JavaScript codes on administrator's browser. Hacker can exploit this vulnerability (changing root password) by XSS or CSRF. Hacker will create a website and put those codes into source. If hacker wants to exploit this by CSRF, CWP administrator will click hacker's website. But if hacker wants to exploit this by XSS, CWP administrator will click here: (admin's own website). The second vulnerability is remote command execution. Hacker can exploit this vulnerability (remote command execution) by XSS or CSRF too. Again, hacker will create a website and put those codes into source. If hacker wants to exploit this by CSRF, CWP administrator will click hacker's website. But if hacker wants to exploit this by XSS, CWP administrator will click here: (admin's own website).