CVE-2023-29489
40Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 5.3epss 66%
exploitation probability
66%top 1% of all CVEs
observed exploitation
nono source reports it
An issue was discovered in cPanel before 11.109.9999.116. XSS can occur on the cpsrvd error page via an invalid webcall ID, aka SEC-669. The fixed versions are 11.109.9999.116, 11.108.0.13, 11.106.0.18, and 11.102.0.31.
CVSS:3.1/AC:L/AV:L/A:L/C:L/I:L/PR:L/S:U/UI:N
Affected products
n/a · n/a