CVE-2021-31803: XSS
Published Apr 26, 2021
·Updated
cPanel before 94.0.3 allows self-XSS via EasyApache 4 Save Profile (SEC-581).
Affected Software
1 affected component
Cpanel Cpanel<94.0.3
Event History
Apr 26, 2021
CVE Published
via MITRE·07:30 AM
Data Sourced
via MITRE·07:30 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-31803?
The severity of CVE-2021-31803 is medium (6.1).
2
How does CVE-2021-31803 vulnerability affect cPanel?
CVE-2021-31803 allows self-XSS via EasyApache 4 Save Profile in cPanel versions before 94.0.3.
3
What is the Common Weakness Enumeration (CWE) for CVE-2021-31803?
The CWE for CVE-2021-31803 is CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')).
4
How can I fix the CVE-2021-31803 vulnerability in cPanel?
To fix the CVE-2021-31803 vulnerability in cPanel, update to version 94.0.3 or newer.
5
Where can I find more information about CVE-2021-31803?
More information about CVE-2021-31803 can be found in the cPanel 94 change log: [link](https://docs.cpanel.net/changelogs/94-change-log/).