CVE-2016-10801: High severity Cpanel Cpanel vulnerability
Published Aug 7, 2019
·Updated
cPanel before 58.0.4 has improper session handling for shared users (SEC-139).
Affected Software
3 affected components
Cpanel Cpanel>=11.54.0.0<11.54.0.26
Cpanel Cpanel>=55.9999.61<56.0.27
Cpanel Cpanel>=57.9999.48<58.0.4
Event History
Aug 7, 2019
CVE Published
via MITRE·12:23 PM
Data Sourced
via MITRE·12:23 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10801?
CVE-2016-10801 is classified as a medium severity vulnerability due to improper session handling.
2
How do I fix CVE-2016-10801?
To fix CVE-2016-10801, you should upgrade cPanel to version 58.0.4 or later.
3
What versions of cPanel are affected by CVE-2016-10801?
CVE-2016-10801 affects cPanel versions prior to 58.0.4, specifically those in the ranges up to 11.54.0.26 and 56.0.27.
4
What are the risks associated with CVE-2016-10801?
The risks associated with CVE-2016-10801 include potential session hijacking and unauthorized access to shared user accounts.
5
Is CVE-2016-10801 still a threat to my system?
CVE-2016-10801 is no longer a threat if cPanel is updated to version 58.0.4 or newer.