CVE-2016-10806: XSS
Published Aug 7, 2019
·Updated
cPanel before 57.9999.54 allows self XSS on the Paper Lantern Landing Page (SEC-110).
Affected Software
3 affected components
Cpanel Cpanel>=11.54.0.0<11.54.0.24
Cpanel Cpanel>=55.9999.61<56.0.15
Cpanel Cpanel>=57.9999.48<57.9999.54
Event History
Aug 7, 2019
CVE Published
via MITRE·12:28 PM
Data Sourced
via MITRE·12:28 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10806?
CVE-2016-10806 has a moderate severity rating due to its potential for self XSS exploitation.
2
How do I fix CVE-2016-10806?
To fix CVE-2016-10806, upgrade your cPanel installation to version 57.9999.54 or later.
3
Which versions of cPanel are affected by CVE-2016-10806?
CVE-2016-10806 affects cPanel versions prior to 57.9999.54, including versions from 55.9999.61 to 56.0.15 and all versions up to 11.54.0.24.
4
What type of vulnerability is CVE-2016-10806?
CVE-2016-10806 is classified as a self XSS vulnerability allowed through the Paper Lantern Landing Page.
5
Is CVE-2016-10806 present in the latest cPanel versions?
No, CVE-2016-10806 has been addressed and is not present in the latest cPanel versions after 57.9999.54.