CVE-2016-10815: Infoleak
Published Aug 1, 2019
·Updated
cPanel before 57.9999.54 allows arbitrary file-read operations for Webmail accounts via Branding APIs (SEC-120).
Affected Software
4 affected components
Cpanel Cpanel>=11.50.0.4<11.50.6.2
Cpanel Cpanel>=11.52.6.0<11.52.6.1
Cpanel Cpanel>=11.54.0.0<11.54.0.24
Cpanel Cpanel>=11.56.0.1<56.0.15
Event History
Aug 1, 2019
CVE Published
via MITRE·06:53 PM
Data Sourced
via MITRE·06:53 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10815?
CVE-2016-10815 has a high severity rating due to its potential for unauthorized arbitrary file reading.
2
How do I fix CVE-2016-10815?
To fix CVE-2016-10815, upgrade cPanel to version 57.9999.54 or later.
3
Who is affected by CVE-2016-10815?
cPanel versions prior to 57.9999.54, specifically versions in the ranges 11.50.0.4 to 11.50.6.2, 11.52.6.0 to 11.52.6.1, 11.54.0.0 to 11.54.0.24, and 56.0.1 to 56.0.15 are affected by CVE-2016-10815.
4
What types of operations can be exploited in CVE-2016-10815?
CVE-2016-10815 allows for arbitrary file-read operations via Branding APIs which can compromise webmail accounts.
5
When was CVE-2016-10815 disclosed?
CVE-2016-10815 was disclosed in 2016, highlighting vulnerabilities in cPanel's handling of Webmail account security.