CVE-2020-10114: XSS
Published Mar 17, 2020
·Updated
cPanel before 84.0.20 allows stored self-XSS via the HTML file editor (SEC-535).
Affected Software
2 affected components
Cpanel Cpanel>=77.9999.110<78.0.45
Cpanel Cpanel>=83.9999.115<84.0.20
Event History
Mar 17, 2020
CVE Published
via MITRE·02:33 PM
Data Sourced
via MITRE·02:33 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this cPanel vulnerability?
The vulnerability ID for this cPanel vulnerability is CVE-2020-10114.
2
What is the title of this vulnerability?
The title of this vulnerability is 'cPanel before 84.0.20 allows stored self-XSS via the HTML file editor (SEC-535).'
3
What is the severity of CVE-2020-10114?
The severity of CVE-2020-10114 is medium (6.1).
4
How can this vulnerability impact me?
This vulnerability can allow an attacker to execute malicious scripts in a victim's browser by tricking them into opening a specially crafted HTML file.
5
How do I fix CVE-2020-10114?
To fix CVE-2020-10114, you should update cPanel to version 84.0.20 or newer.