CVE 8.3 HIGH

CVE-2026-32993_CVE-2026-32993

8.3 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L

Description

Improper sanitization of the `status` query parameter of the `/unprotected/nova_error` endpoint allows unauthenticated attacker to inject arbitrary HTTP header to the response.

Basic Information

ID CVE-2026-32993
Source hackerone
Published May 13, 2026 at 22:06

Affected Product

Vendor WebPros
Product cPanel
Version 11.132.0.0
Affected Versions WebPros cPanel 11.132.0.0
WebPros cPanel 11.134.0.0
WebPros cPanel 11.136.0.0
WebPros WP Squared 11.132.1.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.