CVE-2017-18473: XSS
Published Aug 5, 2019
·Updated
cPanel before 62.0.4 allows self XSS on the webmail Password and Security page (SEC-199).
Affected Software
5 affected components
Cpanel Cpanel>=11.54.0.0<11.54.0.36
Cpanel Cpanel>=55.9999.61<56.0.43
Cpanel Cpanel>=57.9999.48<58.0.43
Cpanel Cpanel>=59.9999.58<60.0.35
Cpanel Cpanel>=61.9999.55<62.0.4
Event History
Aug 5, 2019
CVE Published
via MITRE·12:43 PM
Data Sourced
via MITRE·12:43 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18473?
CVE-2017-18473 has been classified as a moderate severity vulnerability that allows self XSS on the webmail Password and Security page.
2
How do I fix CVE-2017-18473?
To fix CVE-2017-18473, upgrade cPanel to version 62.0.4 or later.
3
What versions of cPanel are affected by CVE-2017-18473?
CVE-2017-18473 affects cPanel versions prior to 62.0.4, including multiple older versions.
4
Is CVE-2017-18473 exploitable remotely?
CVE-2017-18473 is not exploitable remotely as it involves self XSS, which requires user interaction.
5
What should I do if I cannot upgrade from cPanel version prior to 62.0.4?
If unable to upgrade, implement security measures to restrict access to the webmail Password and Security page.