Home
HIGH: 8.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:LDefault status
unaffected
11.132.0.0 (semver) before 11.132.0.32
affected
11.134.0.0 (semver) before 11.134.0.26
affected
11.136.0.0 (semver) before 11.136.0.10
affected
Default status
unaffected
11.132.1.0 (semver) before 11.136.1.12
affected
Description
Improper sanitization of the `status` query parameter of the `/unprotected/nova_error` endpoint allows unauthenticated attacker to inject arbitrary HTTP header to the response.
Problem types
Product status
11.132.0.0 (semver) before 11.132.0.32
11.134.0.0 (semver) before 11.134.0.26
11.136.0.0 (semver) before 11.136.0.10
11.132.1.0 (semver) before 11.136.1.12
References
support.cpanel.net/...el-WHM-WP2-Security-Update-May-13-2026