Vulnerabilities
Vulnerable Software
Cpanel:  >> Cpanel  >> 11.54.0.30  Security Vulnerabilities
cPanel before 60.0.25 allows stored XSS in api1_listautoresponders (SEC-179).
CVSS Score
5.4
EPSS Score
0.003
Published
2019-08-06
cPanel before 60.0.25 allows stored XSS in the ftp_sessions API (SEC-180).
CVSS Score
5.4
EPSS Score
0.003
Published
2019-08-06
cPanel before 60.0.25 allows self XSS in the UI_confirm API (SEC-180).
CVSS Score
5.4
EPSS Score
0.003
Published
2019-08-06
cPanel before 60.0.25 allows self stored XSS in postgres API1 listdbs (SEC-181).
CVSS Score
5.4
EPSS Score
0.003
Published
2019-08-06
cPanel before 60.0.25 allows self stored XSS in SSL_listkeys (SEC-182).
CVSS Score
5.4
EPSS Score
0.003
Published
2019-08-06
cPanel before 60.0.25 allows self XSS in the alias upload interface (SEC-184).
CVSS Score
5.4
EPSS Score
0.003
Published
2019-08-06
cPanel before 60.0.25 allows attackers to discover file contents during file copy operations (SEC-185).
CVSS Score
6.5
EPSS Score
0.003
Published
2019-08-06
cPanel before 60.0.25 allows members of the nobody group to read Apache HTTP Server SSL keys (SEC-186).
CVSS Score
6.5
EPSS Score
0.003
Published
2019-08-06
The Host Access Control feature in cPanel before 60.0.25 mishandles actionless host.deny entries (SEC-187).
CVSS Score
8.1
EPSS Score
0.003
Published
2019-08-06
cPanel before 62.0.4 allows self XSS on the webmail Password and Security page (SEC-199).
CVSS Score
5.4
EPSS Score
0.003
Published
2019-08-05


Contact Us

Shodan ® - All rights reserved