Inappropriate Encoding for Output Context
CVE-2020-29135
Summary
cPanel before 90.0.17 has multiple instances of URL parameter injection (SEC-567).
- LOW
- NETWORK
- LOW
- CHANGED
- REQUIRED
- LOW
- NONE
- NONE
CWE-838 - Inappropriate Encoding for Output Context
The software uses or specifies an encoding when generating output to a downstream component, but the specified encoding is not the same as the encoding that is expected by the downstream component.
References
Advisory Timeline
- Published