CVE-2016-10795: XSS
Published Aug 6, 2019
·Updated
cPanel before 59.9999.145 allows stored XSS in the WHM tailupcp2.cgi interface (SEC-156).
Affected Software
5 affected components
Cpanel Cpanel>=11.51.9999.98<11.52.6.6
Cpanel Cpanel>=11.54.0.0<11.54.0.29
Cpanel Cpanel>=55.9999.61<56.0.34
Cpanel Cpanel>=57.9999.48<58.0.29
Cpanel Cpanel>=59.9999.58<59.9999.145
Event History
Aug 6, 2019
CVE Published
via MITRE·01:06 PM
Data Sourced
via MITRE·01:06 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10795?
CVE-2016-10795 is classified as a stored XSS vulnerability, which can lead to significant security risks.
2
How do I fix CVE-2016-10795?
To fix CVE-2016-10795, you should upgrade to cPanel version 60 or later that is free from this vulnerability.
3
What versions of cPanel are affected by CVE-2016-10795?
CVE-2016-10795 affects cPanel versions before 59.9999.145.
4
What type of vulnerability is CVE-2016-10795?
CVE-2016-10795 is a stored Cross-Site Scripting (XSS) vulnerability found in the WHM interface.
5
Who is impacted by CVE-2016-10795?
Anyone using affected versions of cPanel prior to the fix in version 60 is at risk from CVE-2016-10795.