Impact
A stored cross‑site scripting vulnerability was discovered in the Manage SSL Hosts interface of WHM. An attacker who can submit a malicious payload through this interface can have the script stored and later executed in the browser context of any user who visits the page. The stored code can perform actions as the victim, leading to arbitrary code execution and full compromise of the affected server.
Affected Systems
The flaw affects installations of the WHM administration tool from cPanel and the WP Squared product suite offered by Webpros. No specific version ranges were disclosed in the advisory, so any installation using the Manage SSL Hosts page is potentially vulnerable until a patch is applied.
Risk and Exploitability
The vulnerability carries a CVSS score of 9, indicating high severity. The EPSS score is not available, and the issue is not listed in CISA’s KEV catalog. The likely attack vector is an attacker who can inject content into the Manage SSL Hosts form, which is inferred from the description to require valid WHM credentials or the ability to trick an injected, the payload is executed views the page, immediately granting attacker‑controlled code execution.
OpenCVE Enrichment