CVE-2023-29489

An issue was discovered in cPanel before 11.109.9999.116. XSS can occur on the cpsrvd error page via an invalid webcall ID, aka SEC-669. The fixed versions are 11.109.9999.116, 11.108.0.13, 11.106.0.18, and 11.102.0.31.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
cpanelcpanel
𝑥
< 11.102.0.31
cpanelcpanel
11.104.0 ≤
𝑥
< 11.106.0.18
cpanelcpanel
11.108.0 ≤
𝑥
< 11.108.0.13
cpanelcpanel
11.109.0 ≤
𝑥
< 11.109.9999.116
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
cpanelcpanel
𝑥
< 11.109.9999.116
ADP