CVE-2017-11441

high-risk
Published 2017-07-19

The WHM Upload Locale interface in cPanel before 56.0.51, 58.x before 58.0.52, 60.x before 60.0.45, 62.x before 62.0.27, 64.x before 64.0.33, and 66.x before 66.0.2 has XSS via a locale filename, aka SEC-297.

Do I need to act?

-
0.29% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
5
CVSS 5.4/10 Medium
NETWORK / LOW complexity

Affected Products (20)

Whm
Whm
Whm
Whm
Whm
Whm
Whm
Whm
Whm
Whm
Whm
Whm
Whm
Whm
Whm
Whm
Whm
Whm
Whm
Whm

Affected Vendors

53
/ 100
high-risk
Severity 21/34 · High
Exploitability 1/34 · Minimal
Exposure 31/34 · Critical