CVE-2019-17377: XSS
Published Oct 9, 2019
·Updated
cPanel before 82.0.15 allows self XSS in LiveAPI example scripts (SEC-524).
Affected Software
2 affected components
Cpanel Cpanel>=77.9999.110<78.0.39
Cpanel Cpanel>=81.9999.242<82.0.15
Event History
Oct 9, 2019
CVE Published
via MITRE·03:10 PM
Data Sourced
via MITRE·03:10 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-17377?
CVE-2019-17377 has a medium severity rating due to its potential for self XSS vulnerabilities.
2
How do I fix CVE-2019-17377?
To fix CVE-2019-17377, upgrade cPanel to version 82.0.15 or later.
3
Who is affected by CVE-2019-17377?
CVE-2019-17377 affects all cPanel versions prior to 82.0.15 and those in the 77.x or 81.x versions.
4
What is self XSS in relation to CVE-2019-17377?
Self XSS in CVE-2019-17377 occurs when a user is tricked into executing malicious scripts they control in their own browser.
5
Is CVE-2019-17377 specific to certain cPanel features?
Yes, CVE-2019-17377 specifically impacts LiveAPI example scripts within cPanel.