CVE-2017-18471: XSS
Published Aug 5, 2019
·Updated
cPanel before 62.0.4 allows self XSS on the paperlantern password-change screen (SEC-197).
Affected Software
5 affected components
Cpanel Cpanel>=11.54.0.0<11.54.0.36
Cpanel Cpanel>=55.9999.61<56.0.43
Cpanel Cpanel>=57.9999.48<58.0.43
Cpanel Cpanel>=59.9999.58<60.0.35
Cpanel Cpanel>=61.9999.55<62.0.4
Event History
Aug 5, 2019
CVE Published
via MITRE·12:42 PM
Data Sourced
via MITRE·12:42 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18471?
CVE-2017-18471 is classified as a medium severity vulnerability due to its potential for self XSS attacks.
2
How do I fix CVE-2017-18471?
To fix CVE-2017-18471, update your cPanel installation to version 62.0.4 or later.
3
What type of vulnerability is CVE-2017-18471?
CVE-2017-18471 is a self Cross-Site Scripting (XSS) vulnerability occurring on the password-change screen in cPanel.
4
Which versions of cPanel are affected by CVE-2017-18471?
CVE-2017-18471 affects cPanel versions prior to 62.0.4, specifically versions 55.9999.61 to 61.9999.55.
5
Who is impacted by CVE-2017-18471?
Users of cPanel versions below 62.0.4 may be impacted by CVE-2017-18471, particularly those using the paper_lantern theme.