CVE-2019-17378: XSS
Published Oct 9, 2019
·Updated
cPanel before 82.0.15 allows self XSS in the SSL Key Delete interface (SEC-526).
Affected Software
2 affected components
Cpanel Cpanel>=77.9999.110<78.0.39
Cpanel Cpanel>=81.9999.242<82.0.15
Event History
Oct 9, 2019
CVE Published
via MITRE·03:10 PM
Data Sourced
via MITRE·03:10 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-17378?
CVE-2019-17378 is classified as a low severity vulnerability affecting cPanel versions before 82.0.15.
2
How do I fix CVE-2019-17378?
To fix CVE-2019-17378, upgrade to cPanel version 82.0.15 or later.
3
What type of vulnerability is CVE-2019-17378?
CVE-2019-17378 is a self XSS vulnerability found in the SSL Key Delete interface of cPanel.
4
Which cPanel versions are affected by CVE-2019-17378?
CVE-2019-17378 affects cPanel versions from 77.9999.110 up to 82.0.14.
5
Is CVE-2019-17378 easy to exploit?
CVE-2019-17378 is considered easy to exploit due to its self XSS nature.