An issue was discovered in cPanel before 11.109.9999.116. XSS can occur on the cpsrvd error page via an invalid webcall ID, aka SEC-669. The fixed versions are 11.109.9999.116, 11.108.0.13, 11.106.0.18, and 11.102.0.31.
https://github.com/Thuankobtcode/CVE-2023-29489
https://github.com/krlabs/cpanel-vulnerabilities
https://github.com/some-man1/CVE-2023-29489
https://github.com/ViperM4sk/cpanel-xss-177
https://github.com/zerbaliy3v/nuclei-cve-2023-all-templates
https://github.com/zerbaliy3v/cusom-nuclei-templates
https://github.com/Abdullah7-ma/CVE-2023-29489
https://github.com/1337r0j4n/CVE-2023-29489
https://github.com/whalebone7/EagleEye
https://github.com/haxor1337x/Scanner-CVE-2023-29489
https://github.com/ipk1/CVE-2023-29489.py
https://github.com/learnerboy88/CVE-2023-29489
https://forums.cpanel.net/threads/cpanel-tsr-2023-0001-full-disclosure.708949/
https://blog.assetnote.io/2023/04/26/xss-million-websites-cpanel/