First published: Wed Aug 07 2019(Updated: )
cPanel before 58.0.4 allows demo-mode escape via Site Templates and Boxtrapper API calls (SEC-138).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cpanel Cpanel | >=55.9999.61<56.0.27 | |
Cpanel Cpanel | >=57.9999.48<58.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-10800 has been classified with a moderate severity due to potential demo-mode escape vulnerabilities.
To fix CVE-2016-10800, upgrade your cPanel software to version 58.0.4 or later.
CVE-2016-10800 affects cPanel versions prior to 58.0.4 and versions between 55.9999.61 and 56.0.27 as well as between 57.9999.48 and 58.0.4.
The impact of CVE-2016-10800 allows unauthorized users to escape demo mode through Site Templates and Boxtrapper API calls.
CVE-2016-10800 is considered a type of local exploit, as it requires authenticated access to exploit the vulnerability.