5.4

CVE-2017-11441

The WHM Upload Locale interface in cPanel before 56.0.51, 58.x before 58.0.52, 60.x before 60.0.45, 62.x before 62.0.27, 64.x before 64.0.33, and 66.x before 66.0.2 has XSS via a locale filename, aka SEC-297.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CpanelWhm Version <= 56.0.50
CpanelWhm Version58.0.3
CpanelWhm Version58.0.4
CpanelWhm Version58.0.5
CpanelWhm Version58.0.6
CpanelWhm Version58.0.7
CpanelWhm Version58.0.8
CpanelWhm Version58.0.11
CpanelWhm Version58.0.12
CpanelWhm Version58.0.13
CpanelWhm Version58.0.17
CpanelWhm Version58.0.19
CpanelWhm Version58.0.20
CpanelWhm Version58.0.23
CpanelWhm Version58.0.24
CpanelWhm Version58.0.25
CpanelWhm Version58.0.26
CpanelWhm Version58.0.27
CpanelWhm Version58.0.28
CpanelWhm Version58.0.29
CpanelWhm Version58.0.30
CpanelWhm Version58.0.31
CpanelWhm Version58.0.32
CpanelWhm Version58.0.34
CpanelWhm Version58.0.36
CpanelWhm Version58.0.37
CpanelWhm Version58.0.41
CpanelWhm Version58.0.43
CpanelWhm Version58.0.44
CpanelWhm Version58.0.45
CpanelWhm Version58.0.46
CpanelWhm Version58.0.47
CpanelWhm Version58.0.48
CpanelWhm Version58.0.49
CpanelWhm Version58.0.50
CpanelWhm Version58.0.51
CpanelWhm Version60.0.3
CpanelWhm Version60.0.4
CpanelWhm Version60.0.5
CpanelWhm Version60.0.6
CpanelWhm Version60.0.8
CpanelWhm Version60.0.9
CpanelWhm Version60.0.10
CpanelWhm Version60.0.11
CpanelWhm Version60.0.12
CpanelWhm Version60.0.13
CpanelWhm Version60.0.14
CpanelWhm Version60.0.15
CpanelWhm Version60.0.17
CpanelWhm Version60.0.18
CpanelWhm Version60.0.19
CpanelWhm Version60.0.22
CpanelWhm Version60.0.24
CpanelWhm Version60.0.25
CpanelWhm Version60.0.26
CpanelWhm Version60.0.27
CpanelWhm Version60.0.28
CpanelWhm Version60.0.31
CpanelWhm Version60.0.32
CpanelWhm Version60.0.34
CpanelWhm Version60.0.35
CpanelWhm Version60.0.36
CpanelWhm Version60.0.37
CpanelWhm Version60.0.38
CpanelWhm Version60.0.39
CpanelWhm Version60.0.42
CpanelWhm Version60.0.43
CpanelWhm Version60.0.44
CpanelWhm Version62.0.1
CpanelWhm Version62.0.2
CpanelWhm Version62.0.4
CpanelWhm Version62.0.5
CpanelWhm Version62.0.6
CpanelWhm Version62.0.7
CpanelWhm Version62.0.8
CpanelWhm Version62.0.9
CpanelWhm Version62.0.10
CpanelWhm Version62.0.11
CpanelWhm Version62.0.12
CpanelWhm Version62.0.14
CpanelWhm Version62.0.15
CpanelWhm Version62.0.16
CpanelWhm Version62.0.17
CpanelWhm Version62.0.19
CpanelWhm Version62.0.20
CpanelWhm Version62.0.23
CpanelWhm Version62.0.24
CpanelWhm Version62.0.26
CpanelWhm Version64.0.0
CpanelWhm Version64.0.1
CpanelWhm Version64.0.2
CpanelWhm Version64.0.3
CpanelWhm Version64.0.4
CpanelWhm Version64.0.7
CpanelWhm Version64.0.9
CpanelWhm Version64.0.11
CpanelWhm Version64.0.12
CpanelWhm Version64.0.13
CpanelWhm Version64.0.14
CpanelWhm Version64.0.15
CpanelWhm Version64.0.17
CpanelWhm Version64.0.18
CpanelWhm Version64.0.19
CpanelWhm Version64.0.20
CpanelWhm Version64.0.21
CpanelWhm Version64.0.22
CpanelWhm Version64.0.24
CpanelWhm Version64.0.27
CpanelWhm Version64.0.28
CpanelWhm Version64.0.29
CpanelWhm Version64.0.30
CpanelWhm Version64.0.31
CpanelWhm Version64.0.32
CpanelWhm Version66.0.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.29% 0.492
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.4 2.3 2.7
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.