First published: Thu Aug 01 2019(Updated: )
cPanel before 11.54.0.4 allows self XSS in the WHM PHP Configuration editor interface (SEC-84).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cpanel Cpanel | >=11.48.0.5<11.48.5.2 | |
Cpanel Cpanel | >=11.50.0.4<11.50.4.3 | |
Cpanel Cpanel | >=11.52.2.1<11.52.2.4 | |
Cpanel Cpanel | >=11.54.0.0<11.54.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-10851 has been classified as a medium severity vulnerability due to its potential for exploitation.
To resolve CVE-2016-10851, upgrade to cPanel version 11.54.0.4 or later.
CVE-2016-10851 allows for self XSS (Cross-Site Scripting) attacks in the WHM PHP Configuration editor.
CVE-2016-10851 affects cPanel versions prior to 11.54.0.4, including versions 11.48.5.2 to 11.48.0.5, 11.50.4.3 to 11.50.0.4, and 11.52.2.4 to 11.52.2.1.
CVE-2016-10851 is not remotely exploitable but requires user interaction for the self XSS attack to occur.