First published: Mon Apr 26 2021(Updated: )
cPanel before 94.0.3 allows self-XSS via EasyApache 4 Save Profile (SEC-581).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cpanel Cpanel | <94.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-31803 is medium (6.1).
CVE-2021-31803 allows self-XSS via EasyApache 4 Save Profile in cPanel versions before 94.0.3.
The CWE for CVE-2021-31803 is CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')).
To fix the CVE-2021-31803 vulnerability in cPanel, update to version 94.0.3 or newer.
More information about CVE-2021-31803 can be found in the cPanel 94 change log: [link](https://docs.cpanel.net/changelogs/94-change-log/).