Cpanel · Cpanel · CVE-2004-1849
**Name of the Vulnerable Software and Affected Versions**
cPanel version 9.1.0
**Description**
The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML. Specifically, the vulnerabilities can be exploited via the `email` parameter to "dodelautores.html" or the `handle` parameter to "addhandle.html".
**Recommendations**
For cPanel version 9.1.0, update to a version that includes a fix for these XSS vulnerabilities. As a temporary workaround, consider restricting access to the "dodelautores.html" and "addhandle.html" pages to minimize the risk of exploitation. Avoid using the `email` and `handle` parameters in the affected pages until the issue is resolved.