Vulnerability Intelligence Report
CVE-2017-11441
The WHM Upload Locale interface in cPanel before 56.0.51, 58.x before 58.0.52, 60.x before 60.0.45, 62.x before 62.0.27, 64.x before 64.0.33, and 66.x before 66.0.2 has XSS via a locale filename, aka SEC-297.
No Active Exploit Signals
CVSS Base Score
5.4
MEDIUM
EPSS Probability:0.51%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| cpanel | whm | 58.0.3, 58.0.4, 58.0.5, 58.0.6, 58.0.7, 58.0.8, 58.0.11, 58.0.12, 58.0.13, 58.0.17, 58.0.19, 58.0.20, 58.0.23, 58.0.24, 58.0.25, 58.0.26, 58.0.27, 58.0.28, 58.0.29, 58.0.30, 58.0.31, 58.0.32, 58.0.34, 58.0.36, 58.0.37, 58.0.41, 58.0.43, 58.0.44, 58.0.45, 58.0.46, 58.0.47, 58.0.48, 58.0.49, 58.0.50, 58.0.51, 60.0.3, 60.0.4, 60.0.5, 60.0.6, 60.0.8, 60.0.9, 60.0.10, 60.0.11, 60.0.12, 60.0.13, 60.0.14, 60.0.15, 60.0.17, 60.0.18, 60.0.19, 60.0.22, 60.0.24, 60.0.25, 60.0.26, 60.0.27, 60.0.28, 60.0.31, 60.0.32, 60.0.34, 60.0.35, 60.0.36, 60.0.37, 60.0.38, 60.0.39, 60.0.42, 60.0.43, 60.0.44, 62.0.1, 62.0.2, 62.0.4, 62.0.5, 62.0.6, 62.0.7, 62.0.8, 62.0.9, 62.0.10, 62.0.11, 62.0.12, 62.0.14, 62.0.15, 62.0.16, 62.0.17, 62.0.19, 62.0.20, 62.0.23, 62.0.24, 62.0.26, 64.0.0, 64.0.1, 64.0.2, 64.0.3, 64.0.4, 64.0.7, 64.0.9, 64.0.11, 64.0.12, 64.0.13, 64.0.14, 64.0.15, 64.0.17, 64.0.18, 64.0.19, 64.0.20, 64.0.21, 64.0.22, 64.0.24, 64.0.27, 64.0.28, 64.0.29, 64.0.30, 64.0.31, 64.0.32, 66.0.1 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.511%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2017-07-19T00:00:00 |
| Published | 2017-07-19T07:00:00 |
| Patch Date | 2017-07-19 |
| Last Updated | 2024-08-05T18:12:39 |
Community Chatter & Buzz