CVE-2019-17376: XSS
Published Oct 9, 2019
·Updated
cPanel before 82.0.15 allows self XSS in the SSL Certificate Upload interface (SEC-521).
Affected Software
2 affected components
Cpanel Cpanel>=77.9999.110<78.0.39
Cpanel Cpanel>=81.9999.242<82.0.15
Event History
Oct 9, 2019
CVE Published
via MITRE·03:09 PM
Data Sourced
via MITRE·03:09 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-17376?
CVE-2019-17376 has a medium severity due to its potential for self XSS attacks in cPanel's SSL Certificate Upload interface.
2
How do I fix CVE-2019-17376?
To fix CVE-2019-17376, upgrade cPanel to version 82.0.15 or later, or apply the relevant security patches.
3
What software versions are affected by CVE-2019-17376?
CVE-2019-17376 affects cPanel versions prior to 82.0.15, as well as versions 77.x and 81.x before specific updates.
4
Can CVE-2019-17376 lead to unauthorized access?
While CVE-2019-17376 allows self XSS, it does not directly lead to unauthorized access outside of the user’s own session.
5
Is CVE-2019-17376 a common vulnerability?
CVE-2019-17376 is specific to cPanel and represents a known risk within web hosting environments that utilize this software.