CVE-2019-20493: XSS
Published Mar 17, 2020
·Updated
cPanel before 82.0.18 allows self-XSS because JSON string escaping is mishandled (SEC-520).
Affected Software
3 affected components
Cpanel Cpanel>=77.9999.110<78.0.43
Cpanel Cpanel>=81.9999.242<82.0.18
Cpanel Cpanel>=83.9999.115<84.0.10
Event History
Mar 17, 2020
CVE Published
via MITRE·02:24 PM
Data Sourced
via MITRE·02:24 PM
Description
Frequently Asked Questions
1
What is CVE-2019-20493?
CVE-2019-20493 is a vulnerability in cPanel before version 82.0.18 that allows for self-XSS due to mishandling of JSON string escaping (SEC-520).
2
How does CVE-2019-20493 affect cPanel?
CVE-2019-20493 affects cPanel versions before 82.0.18, allowing for self-XSS due to mishandling of JSON string escaping.
3
What is the severity of CVE-2019-20493?
The severity of CVE-2019-20493 is medium, with a CVSS score of 6.1.
4
How can I fix CVE-2019-20493?
To fix CVE-2019-20493, upgrade to cPanel version 82.0.18 or higher.
5
Where can I find more information about CVE-2019-20493?
You can find more information about CVE-2019-20493 in the cPanel version 82 Change Log: [link](https://documentation.cpanel.net/display/CL/82+Change+Log).