cPanel through 74 allows XSS via a crafted filename in the logs subdirectory of a user account, because the filename is mishandled during frontend/THEME/raw/index.html rendering.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2018-08-30T22:00:00

Updated: 2024-08-05T10:17:38.376Z

Reserved: 2018-08-30T00:00:00

Link: CVE-2018-16236

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2018-08-30T22:29:00.597

Modified: 2018-10-23T14:12:18.760

Link: CVE-2018-16236

cve-icon Redhat

No data.