CVE-2019-20497: XSS
Published Mar 17, 2020
·Updated
cPanel before 82.0.18 allows stored XSS via WHM Backup Restoration (SEC-533).
Affected Software
3 affected components
Cpanel Cpanel>=77.9999.110<78.0.43
Cpanel Cpanel>=81.9999.242<82.0.18
Cpanel Cpanel>=83.9999.115<84.0.10
Event History
Mar 17, 2020
CVE Published
via MITRE·02:31 PM
Data Sourced
via MITRE·02:31 PM
Description
Frequently Asked Questions
1
What is CVE-2019-20497?
CVE-2019-20497 is a vulnerability in cPanel before 82.0.18 that allows stored XSS via WHM Backup Restoration (SEC-533).
2
What is the severity of CVE-2019-20497?
The severity of CVE-2019-20497 is medium with a CVSS score of 5.4.
3
Which software versions are affected by CVE-2019-20497?
The software versions affected by CVE-2019-20497 are cPanel versions 77.9999.110 to 78.0.43, 81.9999.242 to 82.0.18, and 83.9999.115 to 84.0.10.
4
How can I fix CVE-2019-20497?
To fix CVE-2019-20497, you should update cPanel to version 82.0.18 or higher.
5
Where can I find more information about CVE-2019-20497?
You can find more information about CVE-2019-20497 on the cPanel documentation website.