Share on social
April 26, 2023
Lorem ipsum
It is possible to execute arbitrary JavaScript, pre-authentication in the context of a victim, on almost every port of a webserver using cPanel within its default setup.
Even on port 80 and 443, it is possible to reach the /cpanelwebcall/ directory as it is being proxied to the cPanel management ports by Apache.
Because of this, an attacker can not only attack the management ports of cPanel but also the applications that are running on port 80 and 443.
Due to the fact that the cPanel management ports are vulnerable to this cross-site scripting attack, an attacker could leverage this vulnerability to hijack a legitimate user’s cPanel session.
Once acting on behalf of an authenticated user of cPanel, it is usually trivial to upload a web shell and gain command execution.
The following versions are affected by this cross-site scripting vulnerability:
cPanel is a web hosting control panel software that is deployed widely across the internet.
This vulnerability can be remediated by upgrading to any of the following cPanel versions or above:
cPanel’s official advisory can be found here.
The blog post detailing the steps taken for the discovery of this vulnerability can be found here.
Shubham Shah - Assetnote Security Research Team
The timeline for this disclosure process can be found below: