id: CVE-2023-29489 info: name: cPanel - Cross-Site Scripting author: DhiyaneshDk severity: medium reference: https://blog.assetnote.io/2023/04/26/xss-million-websites-cpanel/ metadata: verified: "true" shodan-query: title:"cPanel" tags: cve,cve2023,cpanel,xss http: - method: GET path: - '{{BaseURL}}/cpanelwebcall/aaaaaaaaaaaa' matchers-condition: and matchers: - type: word part: body words: - 'aaaaaaaaaaaa' - 'Invalid webcall ID:' condition: and - type: status status: - 400