Vulnerability record · CVE-2023-29489 · published 27 April 2023
CVE-2023-29489: cPanel cpsrvd error page reflected XSS via invalid webcall ID
Cpanel · Cpanel
cPanel before 11.109.9999.116 reflects an invalid webcall ID into the cpsrvd error page without proper output encoding, allowing reflected cross-site scripting (CWE-79, SEC-669). Because cPanel is widely deployed on hosting servers, a crafted link can run script in the context of the cPanel interface for any user who opens it.
Description
An issue was discovered in cPanel before 11.109.9999.116. XSS can occur on the cpsrvd error page via an invalid webcall ID, aka SEC-669. The fixed versions are 11.109.9999.116, 11.108.0.13, 11.106.0.18, and 11.102.0.31.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityPublic exploit code exists and EPSS is very high (99.2nd percentile), but the flaw requires user interaction and yields limited direct impact, keeping it below critical.
What it is
cPanel before 11.109.9999.116 reflects an invalid webcall ID into the cpsrvd error page without proper output encoding, allowing reflected cross-site scripting (CWE-79, SEC-669). Because cPanel is widely deployed on hosting servers, a crafted link can run script in the context of the cPanel interface for any user who opens it.
Impact
An attacker can execute arbitrary script in a victim's browser in the cPanel origin, potentially stealing session data or performing actions as the logged-in user. The CVSS scope change (S:C) means impact can extend beyond the vulnerable component.
Attack surface
Reached over the network via a crafted URL to the cpsrvd error page; no authentication is required to trigger the reflection, but the victim must click the link (UI:R).
Exploitation
Not listed in CISA KEV, but EPSS is 0.65533 (99.2nd percentile) and both references are tagged Exploit, indicating public exploit code and active interest.
What to do
- Upgrade cPanel to 11.109.9999.116, 11.108.0.13, 11.106.0.18, or 11.102.0.31 (or later) immediately.
- If patching is delayed, restrict access to cpsrvd ports (2082/2083/2086/2087) to trusted networks or place them behind a VPN.
- Deploy a WAF rule to block requests with script payloads in the webcall ID parameter on cpsrvd error pages.
- Enable a Content-Security-Policy on cPanel-facing endpoints to reduce script execution impact.
- Audit cPanel access logs for suspicious webcall ID values and rotate credentials if compromise is suspected.
Detection
- Search web/proxy logs for requests to cpsrvd error pages containing script tags, event handlers, or encoded payloads in the webcall ID parameter.
- Monitor for outbound requests or referrers from cPanel hosts to attacker-controlled domains following error-page hits.
- Alert on repeated 4xx responses from cpsrvd with unusual query strings from a single source.
- Review cPanel authentication and session logs for anomalous logins after suspected XSS delivery.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-29489 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-29489), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.