id: PYSEC-2018-107 details: ajenticp (aka Ajenti Docker control panel) for Ajenti through v1.2.23.13 has XSS via a filename that is mishandled in File Manager. affected: - package: name: ajenti ecosystem: PyPI purl: pkg:pypi/ajenti ranges: - type: ECOSYSTEM events: - introduced: "0" versions: - 0.99.11 - 0.99.19 - 0.99.20 - 0.99.21 - 0.99.22 - 0.99.23 - 0.99.24 - 0.99.25 - 0.99.26 - 0.99.27 - 0.99.28 - 0.99.29 - 0.99.30 - 0.99.31 - 0.99.32 - 0.99.33 - 0.99.34 - 0.99.35 - 0.99.36 - 0.99.37 - 0.99.38 - 0.99.39 - 0.99.7 - 0.99.8 - 1.0.0 - 1.0.1 - 1.0.2 - 1.0.3 - 1.0.8 - 1.1.0 - 1.1.1 - 1.1.2 - 1.1.3 - 1.1.4 - 1.1.5 - 1.1.6 - 1.1.8 - 1.1.8.2 - 1.1.9 - 1.1.9.1 - 1.1.9.2 - 1.1.9.3 - 1.2.0 - 1.2.1 - 1.2.10 - 1.2.11 - 1.2.11.1 - 1.2.11.2 - 1.2.13 - 1.2.13.1 - 1.2.13.2 - 1.2.14 - 1.2.14.1 - 1.2.15 - 1.2.15.1 - 1.2.16 - 1.2.16.1 - 1.2.16.2 - 1.2.17 - 1.2.17.1 - 1.2.17.2 - 1.2.18 - 1.2.18.2 - 1.2.18.4 - 1.2.18.5 - 1.2.18.6 - 1.2.19.0 - 1.2.19.1 - 1.2.19.2 - 1.2.19.3 - 1.2.19.4 - 1.2.19.5 - 1.2.19.6 - 1.2.19.7 - 1.2.19.8 - 1.2.2 - 1.2.20.0 - 1.2.20.1 - 1.2.20.10 - 1.2.20.2 - 1.2.20.3 - 1.2.20.4 - 1.2.20.5 - 1.2.20.6 - 1.2.20.7 - 1.2.20.8 - 1.2.20.9 - 1.2.21.0 - 1.2.21.1 - 1.2.21.10 - 1.2.21.11 - 1.2.21.12 - 1.2.21.13 - 1.2.21.14 - 1.2.21.15 - 1.2.21.16 - 1.2.21.17 - 1.2.21.18 - 1.2.21.2 - 1.2.21.21 - 1.2.21.3 - 1.2.21.4 - 1.2.21.5 - 1.2.21.6 - 1.2.21.7 - 1.2.21.8 - 1.2.21.9 - 1.2.22.0 - 1.2.22.1 - 1.2.22.10 - 1.2.22.11 - 1.2.22.12 - 1.2.22.13 - 1.2.22.14 - 1.2.22.16 - 1.2.22.19 - 1.2.22.2 - 1.2.22.23 - 1.2.22.24 - 1.2.22.3 - 1.2.22.4 - 1.2.22.5 - 1.2.22.6 - 1.2.22.7 - 1.2.22.8 - 1.2.23.13 - 1.2.23.2 - 1.2.23.3 - 1.2.23.4 - 1.2.23.5 - 1.2.23.6 - 1.2.23.7 - 1.2.23.8 - 1.2.23.9 - 1.2.3 - 1.2.4 - 1.2.5 - 1.2.6 - 1.2.6.1 - 1.2.6.2 - 1.2.7 - 1.2.8 - 1.2.9 references: - type: WEB url: http://packetstormsecurity.com/files/149898/AjentiCP-1.2.23.13-Cross-Site-Scripting.html - type: WEB url: https://www.exploit-db.com/exploits/45691/ - type: WEB url: https://numanozdemir.com/ajenti-xss.txt - type: ADVISORY url: https://github.com/advisories/GHSA-5pcv-m8w2-62m9 aliases: - CVE-2018-18548 - GHSA-5pcv-m8w2-62m9 modified: "2021-12-13T06:35:03.125488Z" published: "2018-10-24T21:29:00Z"