First published: Thu Aug 01 2019(Updated: )
cPanel before 11.54.0.4 allows self XSS in the X3 Entropy Banner interface (SEC-87).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cpanel Cpanel | >=11.48.0.5<11.48.5.2 | |
Cpanel Cpanel | >=11.50.0.4<11.50.4.3 | |
Cpanel Cpanel | >=11.52.2.1<11.52.2.4 | |
Cpanel Cpanel | >=11.54.0.0<11.54.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-10854 has a medium severity rating as it allows self XSS in the X3 Entropy Banner interface.
To fix CVE-2016-10854, update cPanel to version 11.54.0.4 or later.
CVE-2016-10854 affects cPanel versions prior to 11.54.0.4, including 11.48.0.5 to 11.48.5.2, 11.50.0.4 to 11.50.4.3, and 11.52.2.1 to 11.52.2.4.
CVE-2016-10854 is a Cross-Site Scripting (XSS) vulnerability that can be exploited by attackers through the X3 Entropy Banner.
Any users utilizing impacted versions of cPanel with the X3 Entropy Banner interface are susceptible to CVE-2016-10854.