CVE-2018-20899: XSS
Published Aug 1, 2019
·Updated
cPanel before 71.9980.37 allows stored XSS in the WHM cPAddons installation interface (SEC-398).
Affected Software
4 affected components
Cpanel Cpanel>=61.9999.55<62.0.47
Cpanel Cpanel>=67.9999.64<68.0.39
Cpanel Cpanel>=69.9999.122<70.0.43
Cpanel Cpanel>=71.9980.30<71.9980.37
Event History
Aug 1, 2019
CVE Published
via MITRE·01:55 PM
Data Sourced
via MITRE·01:55 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20899?
CVE-2018-20899 is classified as a medium severity stored XSS vulnerability.
2
How do I fix CVE-2018-20899?
To mitigate CVE-2018-20899, update cPanel to version 71.9980.37 or later.
3
What is the impact of CVE-2018-20899?
CVE-2018-20899 allows attackers to execute arbitrary JavaScript in the context of the victim's browser.
4
Which versions of cPanel are affected by CVE-2018-20899?
CVE-2018-20899 affects cPanel versions prior to 71.9980.37, including 62.x, 68.x, 70.x, and 71.x.
5
Can CVE-2018-20899 lead to data theft?
Yes, CVE-2018-20899 can lead to data theft through malicious scripts executed via stored XSS.