CVE-2019-11193 describes a Cross-Site Scripting (XSS) vulnerability in the FileManager component of InfinitumIT DirectAdmin versions up to 1.561. This flaw, present in CMD_FILE_MANAGER, CMD_SHOW_USER, and CMD_SHOW_RESELLER, allows an unauthenticated attacker to bypass CSRF protection. With a CVSS score of 6.1 (Medium), successful exploitation could lead to limited confidentiality and integrity impacts, potentially allowing an attacker to take over the administration panel through user interaction. While not listed on the KEV catalog and with no known Metasploit or Nuclei modules, public exploit code exists on ExploitDB (EDB-46694), though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.561CPE matchmatch criteria | cpe:2.3:a:directadmin:directadmin:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.