CVE-2023-29489
MEDIUM 6.1EPSS 65.5%
An issue was discovered in cPanel before 11.109.9999.116. XSS can occur on the cpsrvd error page via an invalid webcall ID, aka SEC-669. The fixed versions are 11.109.9999.116, 11.108.0.13, 11.106.0.18, and 11.102.0.31.
- CVSS v3.1
- 6.1 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N - CVSS v3.1
- 5.3 MEDIUM
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L - EPSS
- 65.53% chance of exploitation in the next 30 days, 99th percentile
- Nuclei
- medium · CWE-79
- Published
- 2023-04-27
- Updated
- 2024-08-02
Proof-of-concept exploits (17)
- 0-d3y/CVE-2023-2948913★ · 2024-08-25
- 0-d3y/XSS_191513★ · 2024-08-25
- Abdullah7-ma/CVE-2023-294890★ · 2024-07-10
- Cappricio-Securities/CVE-2023-294890★ · 2024-06-21
- Mostafa-Elguerdawi/CVE-2023-294890★ · 2023-04-29
- S4muraiMelayu1337/CVE-2023-294890★ · 2023-10-17
- SynixCyberCrimeMy/CVE-2023-294890★ · 2023-11-16
- Thuankobtcode/CVE-2023-294892★ · 2025-06-05
- ViperM4sk/cpanel-xss-1770★ · 2023-08-05
- ipk1/CVE-2023-29489.py2★ · 2023-04-28
- learnerboy88/CVE-2023-294890★ · 2023-04-27
- md-thalal/CVE-2023-294890★ · 2024-06-12
- mdaseem03/cpanel_xss_20234★ · 2024-01-31
- mr-sami-x/XSS_191513★ · 2024-08-25
- some-man1/CVE-2023-294890★ · 2024-04-14
- whalebone7/EagleEye7★ · 2023-05-01
- xKore123/cPanel-CVE-2023-294893★ · 2023-04-27