First published: Thu Aug 01 2019(Updated: )
cPanel before 57.9999.54 allows arbitrary file-read operations for Webmail accounts via Branding APIs (SEC-120).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cpanel Cpanel | >=11.50.0.4<11.50.6.2 | |
Cpanel Cpanel | >=11.52.6.0<11.52.6.1 | |
Cpanel Cpanel | >=11.54.0.0<11.54.0.24 | |
Cpanel Cpanel | >=11.56.0.1<56.0.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-10815 has a high severity rating due to its potential for unauthorized arbitrary file reading.
To fix CVE-2016-10815, upgrade cPanel to version 57.9999.54 or later.
cPanel versions prior to 57.9999.54, specifically versions in the ranges 11.50.0.4 to 11.50.6.2, 11.52.6.0 to 11.52.6.1, 11.54.0.0 to 11.54.0.24, and 56.0.1 to 56.0.15 are affected by CVE-2016-10815.
CVE-2016-10815 allows for arbitrary file-read operations via Branding APIs which can compromise webmail accounts.
CVE-2016-10815 was disclosed in 2016, highlighting vulnerabilities in cPanel's handling of Webmail account security.