First published: Mon Aug 05 2019(Updated: )
cPanel before 62.0.4 allows reflected XSS in reset-password interfaces (SEC-198).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cpanel Cpanel | >=55.9999.61<56.0.43 | |
Cpanel Cpanel | >=57.9999.48<58.0.43 | |
Cpanel Cpanel | >=59.9999.58<60.0.35 | |
Cpanel Cpanel | >=61.9999.55<62.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-18472 is considered a moderate severity vulnerability due to its potential for reflected cross-site scripting (XSS) attacks.
To fix CVE-2017-18472, upgrade cPanel to version 62.0.4 or later.
The impact of CVE-2017-18472 allows attackers to execute arbitrary JavaScript in the context of the user’s session on the affected reset-password interface.
CVE-2017-18472 affects cPanel versions earlier than 62.0.4, specifically versions 55.x.x to 62.x.x.
There are no officially recommended workarounds; the best course of action is to update to the latest version of cPanel.