Situation
There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.
Affected Product Versions
| Product | Affected Versions | Patched Versions |
|---|---|---|
| cPanel/WHM | All supported versions |
|
Impact
Successful exploitation allows an unprivileged account holder to execute script in the context of a WHM administrator's session, which can be used to perform administrative actions as that user.
Call to action
Update to the latest patched version: How do I update cPanel/WHM?
Comments
0 comments
Article is closed for comments.