CVE-2018-20933: XSS
Published Aug 1, 2019
·Updated
cPanel before 70.0.23 has Stored XSS via an WHM Edit DNS Zone action (SEC-410).
Affected Software
3 affected components
Cpanel Cpanel>=61.9999.55<62.0.42
Cpanel Cpanel>=67.9999.64<68.0.33
Cpanel Cpanel>=69.9999.122<70.0.23
Event History
Aug 1, 2019
CVE Published
via MITRE·03:49 PM
Data Sourced
via MITRE·03:49 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20933?
CVE-2018-20933 is classified as a medium severity vulnerability due to its potential for stored cross-site scripting (XSS).
2
How do I fix CVE-2018-20933?
To fix CVE-2018-20933, update cPanel to version 70.0.23 or later as it contains the patch for this vulnerability.
3
What software is affected by CVE-2018-20933?
CVE-2018-20933 affects cPanel versions prior to 70.0.23, including certain versions starting from 61.9999.55 to 62.0.42 and from 67.9999.64 to 68.0.33.
4
What type of attack can CVE-2018-20933 facilitate?
CVE-2018-20933 facilitates stored cross-site scripting (XSS) attacks which can allow malicious scripts to run in users' browsers.
5
Is CVE-2018-20933 easily exploitable?
Yes, CVE-2018-20933 is considered easily exploitable due to its applicability in the WHM Edit DNS Zone action.