CVE-2016-10792: High severity Cpanel Cpanel vulnerability
Published Aug 6, 2019
·Updated
cPanel before 59.9999.145 allows code execution in the context of other accounts via mailman list archives (SEC-141).
Affected Software
5 affected components
Cpanel Cpanel>=11.51.9999.98<11.52.6.6
Cpanel Cpanel>=11.54.0.0<11.54.0.29
Cpanel Cpanel>=55.9999.61<56.0.34
Cpanel Cpanel>=57.9999.48<58.0.29
Cpanel Cpanel>=59.9999.58<59.9999.145
Event History
Aug 6, 2019
CVE Published
via MITRE·01:02 PM
Data Sourced
via MITRE·01:02 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10792?
CVE-2016-10792 has a critical severity level due to its potential for code execution in the context of other accounts.
2
How do I fix CVE-2016-10792?
To fix CVE-2016-10792, upgrade to cPanel version 59.9999.146 or later.
3
What versions of cPanel are affected by CVE-2016-10792?
CVE-2016-10792 affects cPanel versions prior to 59.9999.146, including those between 11.51.9999.98 and 11.52.6.6, 11.54.0.0 and 11.54.0.29, and several others within specific version ranges.
4
What exploit does CVE-2016-10792 enable?
CVE-2016-10792 enables code execution through mailman list archives, compromising account security.
5
Is CVE-2016-10792 specific to cPanel configurations?
Yes, CVE-2016-10792 is specifically a vulnerability in cPanel configurations involving email list management.