CVE-2020-29137: XSS
Published Nov 27, 2020
·Updated
cPanel before 90.0.17 allows self-XSS via the WHM Transfer Tool interface (SEC-577).
Affected Software
1 affected component
Cpanel Cpanel<90.0.17
Event History
Nov 27, 2020
CVE Published
via MITRE·01:34 AM
Data Sourced
via MITRE·01:34 AM
Description
Frequently Asked Questions
1
What is CVE-2020-29137?
CVE-2020-29137 is a vulnerability in cPanel that allows self-XSS via the WHM Transfer Tool interface.
2
What is the severity of CVE-2020-29137?
The severity of CVE-2020-29137 is medium with a CVSS score of 6.1.
3
How does CVE-2020-29137 affect cPanel?
CVE-2020-29137 affects cPanel versions up to 90.0.17.
4
How can CVE-2020-29137 be fixed?
To fix CVE-2020-29137, update cPanel to version 90.0.17 or higher.
5
Where can I find more information about CVE-2020-29137?
You can find more information about CVE-2020-29137 in cPanel's change log and the cPanel TSR-2020-0007 full disclosure.