Self-XSS Vulnerability in cPanel WHM Transfer Tool
CVE-2020-29137

6.1MEDIUM

Key Information:

Vendor
Cpanel
Status
Vendor
CVE Published:
27 November 2020

Summary

A self-XSS vulnerability exists in cPanel's WHM Transfer Tool that allows unprivileged users to execute scripts in their own context. This means that through an improper handling of user inputs, attackers can trick users into executing unintended scripts, potentially compromising sensitive data. Users of cPanel are advised to upgrade to version 90.0.17 or later to mitigate this security risk.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.