CVE-2020-26110: XSS
Published Sep 25, 2020
·Updated
cPanel before 88.0.13 allows self XSS via DNS Zone Manager DNSSEC interfaces (SEC-564).
Affected Software
1 affected component
Cpanel Cpanel<88.0.13
Event History
Sep 25, 2020
CVE Published
via MITRE·05:40 AM
Data Sourced
via MITRE·05:40 AM
Description
Frequently Asked Questions
1
What is CVE-2020-26110?
CVE-2020-26110 is a vulnerability in cPanel before version 88.0.13 that allows self cross-site scripting (XSS) via DNS Zone Manager DNSSEC interfaces.
2
How severe is CVE-2020-26110?
CVE-2020-26110 has a severity rating of medium (6.1).
3
What software is affected by CVE-2020-26110?
cPanel version up to but excluding 88.0.13 is affected by CVE-2020-26110.
4
How can I fix CVE-2020-26110?
To fix CVE-2020-26110, you should update your cPanel installation to version 88.0.13 or newer.
5
Where can I find more information about CVE-2020-26110?
You can find more information about CVE-2020-26110 in the cPanel 88.0.13 change log.