Description
The cPanel is vulnerable to the XSS (cross-site scripting). The 'cpanelwebcall' endpoint does not properly sanitize user input.
Remediation
Upgrade to the latest version of cPanel
References
Related Vulnerabilities
Squid Incorrect Conversion between Numeric Types Vulnerability (CVE-2023-46848)
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2020-11057)
WebLogic Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2021-21350)
WordPress Plugin Integrator 'redirect_to' Parameter Cross-Site Scripting (1.32)
WordPress Plugin Ivory Search-WordPress Search Cross-Site Scripting (4.6.6)