S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-29489 Scanner

CVE-2023-29489 scanner - Cross-Site Scripting (XSS) vulnerability in cPanel

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.8k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-29489
6.1
CVSSmedium
Requires local system access · low-privilege account sufficient.

An issue was discovered in cPanel before 11.109.9999.116. XSS can occur on the cpsrvd error page via an invalid webcall ID, aka SEC-669. The fixed versions are 11.109.9999.116, 11.108.0.13, 11.106.0.18, and 11.102.0.31.

Attack Vector
Local
Privileges Req.
Low
User Interaction
None
Affected
n/aby n/a
n/a
cpanelby cpanel
AFFECTED< 11.109.9999.116SAFE ✓≥ 11.109.9999.116
cpanelby cpanel
11.109.9999.116
Updated Aug 22, 2026View on NVD →
Detail

cPanel is a popular web hosting control panel that provides a user-friendly interface for webmasters to manage their websites and servers efficiently. This software is widely used by web hosting companies worldwide, including many big names in the industry. The cPanel interface offers a range of features for website owners, including domain management, email administration, database management, file management, and more. It is a fast and reliable platform that simplifies the management of a web hosting account.

One of the vulnerabilities discovered in cPanel is CVE-2023-29489, also known as SEC-669. This vulnerability can lead to cross-site scripting (XSS) attacks that can be initiated by an invalid web call ID. When this vulnerability is exploited, attackers can execute malicious scripts on the server, allowing them to steal sensitive information, infect the server with malware or take complete control of the server.

If this vulnerability is not patched, it can lead to a variety of serious consequences, such as data breaches, website defacement, server takeovers, and other malicious activities. Attackers can use this vulnerability to target websites and exploit them for their gain. The threat can be detrimental to online businesses, as it can result in financial losses, loss of credibility, and reputational damage.

Thanks to the pro features of the s4e.io platform, those who read this article can learn about vulnerabilities in their digital assets quickly and easily. This platform offers comprehensive security scanning and monitoring tools that can help webmasters and businesses protect their websites and servers against various threats and vulnerabilities. With s4e.io, you can gain a complete understanding of your security posture and take necessary actions to protect your online assets.

 

REFERENCES

Solution Advice

To protect against this vulnerability, webmasters and hosting providers need to take necessary precautions, including installing the latest cPanel update as soon as possible. Here are some additional actions that can be taken to mitigate the risk of exploitation:

  • Ensure that your servers are always up to date with the latest security patches and software updates.
  • Keep a regular backup of your website and server data.
  • Use a web application firewall (WAF) to filter out malicious traffic and protect against XSS attacks.
  • Educate yourself and your team about the latest security threats and vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.