CVE-2016-10853: XSS
Published Aug 1, 2019
·Updated
cPanel before 11.54.0.4 allows stored XSS in the WHM Feature Manager interface (SEC-86).
Affected Software
2 affected components
Cpanel Cpanel>=11.48.0.5<11.48.4.8
Cpanel Cpanel>=11.54.0.0<11.54.0.4
Event History
Aug 1, 2019
CVE Published
via MITRE·02:45 PM
Data Sourced
via MITRE·02:45 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10853?
The severity of CVE-2016-10853 is classified as moderate due to the potential for stored cross-site scripting attacks.
2
How do I fix CVE-2016-10853?
To fix CVE-2016-10853, update cPanel to version 11.54.0.5 or later.
3
What does CVE-2016-10853 allow attackers to do?
CVE-2016-10853 allows attackers to execute stored cross-site scripting through the WHM Feature Manager interface.
4
Which versions of cPanel are affected by CVE-2016-10853?
CVE-2016-10853 affects cPanel versions prior to 11.54.0.5 and those between 11.48.0.5 and 11.48.4.8.
5
Is CVE-2016-10853 a remote vulnerability?
Yes, CVE-2016-10853 is a remote vulnerability as it can be exploited via the web interface.