Cross-site scripting in cPanel - #VU101729
Published: December 12, 2024
cPanel
Detailed vulnerability description
The vulnerability allows a remote attacker to perform self-XSS attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data within the webdiskvbs.cgi script. A remote attacker can trick the victim into injecting a specially crafted payload into a specific form and execute arbitrary HTML and script code in user's browser in context of vulnerable website.