Impact
The vulnerability is a stored cross‑site scripting flaw that allows an attacker to embed malicious code into the WHM Mass Modify Accounts interface, potentially executing arbitrary code on the server. The flaw arises when input provided by a user is stored and later rendered without proper sanitization, permitting code injection that can affect the integrity and confidentiality of the system and its data.
Affected Systems
Products affected include Webpros: WP Squared and Webpros: cPanel. Specific version information is not listed, suggesting that all versions may be vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 9 indicates a high‑severity issue. No EPSS score is available, but the lack of a KEV listing does not diminish the impact of the vulnerability. The attack vector requires access to the WHM Mass Modify Accounts interface, typically available to administrators. An attacker with that access can supply malicious script that persists across sessions, leading to code execution on subsequent page loads. The exploit is straightforward once the authenticated interface is reached, making it likely to be abused if unattended.
OpenCVE Enrichment