CVE-2017-18481: XSS
cPanel before 62.0.4 allows stored XSS in the WHM Account Suspension List interface (SEC-211).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-18481?
CVE-2017-18481 is classified as a medium severity vulnerability due to its potential for stored cross-site scripting (XSS).
How does CVE-2017-18481 affect cPanel users?
CVE-2017-18481 allows attackers to store malicious scripts in the WHM Account Suspension List, potentially impacting users who view that interface.
How do I fix CVE-2017-18481?
To mitigate CVE-2017-18481, update your cPanel to version 62.0.4 or later, as it contains the necessary security fix.
Which versions of cPanel are affected by CVE-2017-18481?
Affected versions of cPanel include all versions prior to 62.0.4, as well as several earlier versions in the 55.x, 56.x, 57.x, 58.x, and 60.x series.
What type of vulnerability is CVE-2017-18481?
CVE-2017-18481 is a stored cross-site scripting (XSS) vulnerability that allows attackers to inject scripts that could be executed in the context of the victim's browser.