CVE-2016-10779: XSS
Published Aug 6, 2019
·Updated
cPanel before 60.0.25 allows stored XSS in api1listautoresponders (SEC-179).
Affected Software
4 affected components
Cpanel Cpanel>=11.54.0.0<11.54.0.33
Cpanel Cpanel>=55.9999.61<56.0.39
Cpanel Cpanel>=57.9999.48<58.0.37
Cpanel Cpanel>=59.9999.58<60.0.25
Event History
Aug 6, 2019
CVE Published
via MITRE·12:50 PM
Data Sourced
via MITRE·12:50 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10779?
CVE-2016-10779 is classified as a medium severity vulnerability due to the potential for stored cross-site scripting (XSS).
2
How do I fix CVE-2016-10779?
To resolve CVE-2016-10779, upgrade cPanel to version 60.0.25 or later to eliminate the stored XSS vulnerability.
3
What versions of cPanel are affected by CVE-2016-10779?
CVE-2016-10779 affects cPanel versions before 60.0.25, including versions 11.54.x, 55.x through 56.0.39, and 57.x through 58.0.37.
4
What kind of attack does CVE-2016-10779 enable?
CVE-2016-10779 allows for stored XSS attacks through the api1_listautoresponders functionality in cPanel.
5
Can CVE-2016-10779 affect user data?
Yes, CVE-2016-10779 can potentially allow attackers to execute malicious scripts that may compromise user data.