First published: Mon Aug 05 2019(Updated: )
cPanel before 62.0.4 allows self XSS on the webmail Password and Security page (SEC-199).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cpanel Cpanel | >=11.54.0.0<11.54.0.36 | |
Cpanel Cpanel | >=55.9999.61<56.0.43 | |
Cpanel Cpanel | >=57.9999.48<58.0.43 | |
Cpanel Cpanel | >=59.9999.58<60.0.35 | |
Cpanel Cpanel | >=61.9999.55<62.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-18473 has been classified as a moderate severity vulnerability that allows self XSS on the webmail Password and Security page.
To fix CVE-2017-18473, upgrade cPanel to version 62.0.4 or later.
CVE-2017-18473 affects cPanel versions prior to 62.0.4, including multiple older versions.
CVE-2017-18473 is not exploitable remotely as it involves self XSS, which requires user interaction.
If unable to upgrade, implement security measures to restrict access to the webmail Password and Security page.