CVE-2023-29489 is a reflected, pre-authentication cross-site scripting flaw in cPanel’s default web-hosting control-panel configuration. Crafted requests to the /cpanelwebcall/ path could execute arbitrary JavaScript in a victim’s browser because Apache proxies that directory to cPanel management ports, including when the request reaches the server through ports 80 or 443.
An attacker could use the flaw to steal or hijack an authenticated cPanel session and, through the victim’s privileges, upload a web shell for potential command execution on the hosted server. cPanel fixed the issue in versions 11.109.9999.116, 11.108.0.13, 11.106.0.18, and 11.102.0.31; affected administrators should ensure their deployments are updated to a remediated release.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
cPanel released fixes for the pre-authentication XSS flaw and publicly disclosed it. Fixed releases included 11.109.9999.116, 11.108.0.13, 11.106.0.18, and 11.102.0.31.
cPanel confirmed the reported reflected XSS vulnerability and assigned it the internal identifier SEC-669.
Shubham Shah of Assetnote disclosed a pre-authentication reflected XSS vulnerability in cPanel to cPanel, which acknowledged receipt of the report the same day.
A technical analysis described exploitation through cPanel's /cpanelwebcall/ error handling, where attacker-controlled invalid webcall IDs reached an unsanitized message_html value. It also found Apache proxy rules could expose the flaw through ports 80 and 443, enabling authenticated-session hijacking and possible web-shell upload; the fix HTML-encodes message_html.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
slcyber.io
Open sourceslcyber.io
Open sourceblog.assetnote.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.