The WHM interface 11.15.0 for cPanel 11.18 prior to 11.18.4 and 11.22 prior to 11.22.3 allows remote malicious users to bypass XSS protection and inject arbitrary script or HTML via repeated, improperly-ordered "<" and ">" characters in the (1) issue parameter to scripts2/knowlegebase, (2) user parameter to scripts2/changeip, (3) search parameter to scripts2/listaccts, and other unspecified vectors.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
cpanel cpanel 11.18 |
||
cpanel cpanel 11.22 |
||
cpanel cpanel 11.18.3 |
||
cpanel cpanel 11.18.1 |
||
cpanel cpanel 11.22.1 |
||
cpanel cpanel 11.22.2 |
||
cpanel cpanel 11.18.2 |