cPanel
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*
- >= 11.132, < 11.132.0.32
- >= 11.134, < 11.134.0.26
- >= 11.136, < 11.136.0.10
A vulnerability exists in cPanel & WHM versions 132 and higher, specifically within the WP Squared component. The issue arises from improper sanitization of the 'status' query parameter in the '/unprotected/nova_error' endpoint. This flaw allows unauthenticated attackers to inject arbitrary HTTP headers into the response.
Exploitation of this vulnerability could lead to the injection of malicious HTTP headers, potentially causing unexpected behavior in the application or client.
Users can update to cPanel & WHM versions 11.132.0.32 and higher, 11.134.0.26 and higher, or 11.136.0.10 and higher. For WP Squared, version 11.136.1.12 and higher is recommended. After updating, verify the cPanel version to ensure the update was successful.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.