#VU101729 Cross-site scripting in cPanel
Published: December 12, 2024
cPanel
cPanel, Inc
Description
The vulnerability allows a remote attacker to perform self-XSS attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data within the webdiskvbs.cgi script. A remote attacker can trick the victim into injecting a specially crafted payload into a specific form and execute arbitrary HTML and script code in user's browser in context of vulnerable website.