CVE-2021-38584: XEE
Published Aug 11, 2021
·Updated
The WHM Locale Upload feature in cPanel before 98.0.1 allows XXE attacks (SEC-585).
Affected Software
1 affected component
Cpanel Cpanel<98.0.1
Event History
Aug 11, 2021
CVE Published
via MITRE·10:56 PM
Data Sourced
via MITRE·10:56 PM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-38584.
2
What is the severity of CVE-2021-38584?
The severity of CVE-2021-38584 is high with a CVSS score of 7.2.
3
What is the affected software for CVE-2021-38584?
The affected software for CVE-2021-38584 is cPanel before version 98.0.1.
4
What type of attacks does CVE-2021-38584 allow?
CVE-2021-38584 allows XXE (XML External Entity) attacks.
5
How can I fix CVE-2021-38584?
To fix CVE-2021-38584, you should update cPanel to version 98.0.1 or later.