CVE-2017-11441

MEDIUM

cPanel WHM < 56.0.51 - Stored Cross-Site Scripting via Locale Filename Upload

Title source: llm
STIX 2.1

Description

The WHM Upload Locale interface in cPanel before 56.0.51, 58.x before 58.0.52, 60.x before 60.0.45, 62.x before 62.0.27, 64.x before 64.0.33, and 66.x before 66.0.2 has XSS via a locale filename, aka SEC-297.

References (1)

Core 1
Core References

Scores

CVSS v3 5.4
EPSS 0.0029
EPSS Percentile 52.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (50)
cpanel/whm 58.0.3
cpanel/whm 58.0.4
cpanel/whm 58.0.5
cpanel/whm 58.0.6
cpanel/whm 58.0.7
cpanel/whm 58.0.8
cpanel/whm 58.0.11
cpanel/whm 58.0.12
cpanel/whm 58.0.13
cpanel/whm 58.0.17
... and 40 more
Published Jul 19, 2017
Tracked Since Feb 18, 2026