CVE-2023-29489

MEDIUM NUCLEI

Cpanel < 11.102.0.31 - XSS

Title source: rule

Description

An issue was discovered in cPanel before 11.109.9999.116. XSS can occur on the cpsrvd error page via an invalid webcall ID, aka SEC-669. The fixed versions are 11.109.9999.116, 11.108.0.13, 11.106.0.18, and 11.102.0.31.

Exploits (20)

nomisec SCANNER 12 stars
by 0-d3y · poc
https://github.com/0-d3y/CVE-2023-29489
nomisec SCANNER 7 stars
by whalebone7 · poc
https://github.com/whalebone7/EagleEye
nomisec SCANNER 4 stars
by mdaseem03 · poc
https://github.com/mdaseem03/cpanel_xss_2023
nomisec STUB 3 stars
by xKore123 · poc
https://github.com/xKore123/cPanel-CVE-2023-29489
nomisec SCANNER 2 stars
by ipk1 · poc
https://github.com/ipk1/CVE-2023-29489.py
nomisec SCANNER 2 stars
by Makurorororororororo · poc
https://github.com/Makurorororororororo/Validate-CVE-2023-29489-scanner-
nomisec SCANNER 1 stars
by Thuankobtcode · poc
https://github.com/Thuankobtcode/CVE-2023-29489
nomisec SCANNER
by tucommenceapousser · poc
https://github.com/tucommenceapousser/CVE-2023-29489.py
nomisec SCANNER
by prasad-1808 · poc
https://github.com/prasad-1808/tool-29489
nomisec SCANNER
by Mostafa-Elguerdawi · poc
https://github.com/Mostafa-Elguerdawi/CVE-2023-29489
nomisec SCANNER
by learnerboy88 · poc
https://github.com/learnerboy88/CVE-2023-29489
nomisec SCANNER
by tucommenceapousser · poc
https://github.com/tucommenceapousser/CVE-2023-29489
nomisec WORKING POC
by ViperM4sk · poc
https://github.com/ViperM4sk/cpanel-xss-177
nomisec SCANNER
by S4muraiMelayu1337 · poc
https://github.com/S4muraiMelayu1337/CVE-2023-29489
nomisec NO CODE
by Abdullah7-ma · poc
https://github.com/Abdullah7-ma/CVE-2023-29489
nomisec SCANNER
by some-man1 · poc
https://github.com/some-man1/CVE-2023-29489
nomisec SCANNER
by md-thalal · poc
https://github.com/md-thalal/CVE-2023-29489
nomisec SCANNER
by Cappricio-Securities · poc
https://github.com/Cappricio-Securities/CVE-2023-29489
nomisec SCANNER
by SynixCyberCrimeMy · poc
https://github.com/SynixCyberCrimeMy/CVE-2023-29489

Nuclei Templates (1)

cPanel < 11.109.9999.116 - Cross-Site Scripting
MEDIUMVERIFIEDby DhiyaneshDk,0xKayala
Shodan: title:"cPanel" || http.title:"cpanel" || cpe:"cpe:2.3:a:cpanel:cpanel" || http.title:"cpanel - api codes"
FOFA: title="cpanel - api codes" || title="cpanel"

Scores

CVSS v3 5.3
EPSS 0.9293
EPSS Percentile 99.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Classification

CWE
CWE-79
Status published

Affected Products (1)

cpanel/cpanel < 11.102.0.31

Timeline

Published Apr 27, 2023
Tracked Since Feb 18, 2026