Description

Cross-site scripting (XSS) and local file inclusion (LFI) vulnerabilities exist in CPanel 11.x. Multiple parameters in the web interface are not properly sanitized, allowing injection of JavaScript and inclusion of local files.

Impact

XSS allows attackers to steal session cookies and hijack administrator accounts. LFI allows reading arbitrary files on the server, potentially exposing configuration files, credentials, and sensitive system data.

Solution

Upgrade to the latest CPanel version which addresses these vulnerabilities.

References