Improper sanitization of the `status` query parameter of the `/unprotected/nova_error` endpoint allows unauthenticated attacker to inject arbitrary HTTP header to the response.
Metrics
Affected Vendors & Products
References
History
Thu, 14 May 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Webpros
Webpros cpanel Webpros wp Squared |
|
| Vendors & Products |
Webpros
Webpros cpanel Webpros wp Squared |
Wed, 13 May 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper sanitization of the `status` query parameter of the `/unprotected/nova_error` endpoint allows unauthenticated attacker to inject arbitrary HTTP header to the response. | |
| Weaknesses | CWE-93 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: hackerone
Published: 2026-05-13T22:06:04.114Z
Updated: 2026-05-13T22:06:04.114Z
Reserved: 2026-03-17T15:00:07.746Z
Link: CVE-2026-32993
No data.
Status : Received
Published: 2026-05-13T22:16:43.143
Modified: 2026-05-13T22:16:43.143
Link: CVE-2026-32993
No data.
ReportizFlow