CVE-2018-20900: XSS
Published Aug 1, 2019
·Updated
cPanel before 71.9980.37 allows stored XSS in the YUM autorepair functionality (SEC-399).
Affected Software
3 affected components
Cpanel Cpanel>=62.0.1<62.0.47
Cpanel Cpanel>=68.0.1<68.0.39
Cpanel Cpanel>=70.0.2<70.0.43
Event History
Aug 1, 2019
CVE Published
via MITRE·01:57 PM
Data Sourced
via MITRE·01:57 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20900?
CVE-2018-20900 has been classified as a medium severity vulnerability due to the potential for stored XSS attacks.
2
How do I fix CVE-2018-20900?
To resolve CVE-2018-20900, you should upgrade to cPanel version 71.9980.37 or later.
3
What software is affected by CVE-2018-20900?
CVE-2018-20900 affects cPanel versions prior to 71.9980.37, specifically versions between 62.0.1 and 62.0.47, 68.0.1 and 68.0.39, and 70.0.2 and 70.0.43.
4
What type of vulnerability is CVE-2018-20900?
CVE-2018-20900 is a stored cross-site scripting (XSS) vulnerability found in the YUM autorepair functionality of cPanel.
5
When was CVE-2018-20900 disclosed?
CVE-2018-20900 was disclosed in 2018 as part of security advisories related to vulnerabilities in cPanel.