CVE-2016-10797: Infoleak
Published Aug 6, 2019
·Updated
cPanel before 58.0.4 allows WHM "Purchase and Install an SSL Certificate" page visitors to list all server domains (SEC-133).
Affected Software
2 affected components
Cpanel Cpanel>=55.9999.61<56.0.27
Cpanel Cpanel>=57.9999.48<58.0.4
Event History
Aug 6, 2019
CVE Published
via MITRE·01:08 PM
Data Sourced
via MITRE·01:08 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10797?
The severity of CVE-2016-10797 is considered medium due to its information disclosure nature.
2
How do I fix CVE-2016-10797?
To fix CVE-2016-10797, upgrade cPanel to version 58.0.4 or later.
3
What type of security issue is CVE-2016-10797?
CVE-2016-10797 is an information disclosure vulnerability that allows unauthorized listing of all server domains.
4
Which versions of cPanel are affected by CVE-2016-10797?
CVE-2016-10797 affects cPanel versions before 58.0.4 and between 55.9999.61 and 56.0.27 and 57.9999.48.
5
What impact does CVE-2016-10797 have on users?
The impact of CVE-2016-10797 on users is the potential exposure of sensitive domain information.