CVE-2020-26115: XSS
Published Sep 25, 2020
·Updated
cPanel before 90.0.10 allows self XSS via the Cron Editor interface (SEC-574).
Affected Software
1 affected component
Cpanel Cpanel<90.0.10
Event History
Sep 25, 2020
CVE Published
via MITRE·05:40 AM
Data Sourced
via MITRE·05:40 AM
Description
Frequently Asked Questions
1
What is CVE-2020-26115?
CVE-2020-26115 is a vulnerability in cPanel before version 90.0.10 that allows self XSS via the Cron Editor interface (SEC-574).
2
How severe is CVE-2020-26115?
CVE-2020-26115 has a severity rating of medium with a CVSS score of 6.1.
3
Which software versions are affected by CVE-2020-26115?
CVE-2020-26115 affects cPanel versions up to but not including 90.0.10.
4
How can I fix CVE-2020-26115?
To fix CVE-2020-26115, it is recommended to update cPanel to version 90.0.10 or later.
5
Where can I find more information about CVE-2020-26115?
More information about CVE-2020-26115 can be found in the cPanel version 90 change log: [link](https://docs.cpanel.net/changelogs/90-change-log/).