XSS Vulnerability in cPanel & WHM by cPanel, Inc.
CVE-2012-6449

5.4MEDIUM

Key Information:

Vendor
Cpanel
Status
Vendor
CVE Published:
10 February 2020

Summary

The cPanel & WHM 11.34.0 (build 8) contains a cross-site scripting (XSS) vulnerability in the clientconf.html and detailbw.html pages. This flaw allows attackers to inject malicious scripts into web pages viewed by other users. When the malicious script is executed by the client's browser, it can lead to unauthorized data access and potential compromise of user information. Effective security measures must be implemented to mitigate such vulnerabilities and protect user data.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.