index.php in CentOS-WebPanel.com (aka CWP) CentOS Web Panel through v0.9.8.12 has XSS via the id parameter to the phpini_editor module or the email_address parameter to the mail_add-new module.
- https://www.vulnerability-lab.com/get_content.php?id=1836
No PoCs found on GitHub currently.