First published: Thu Aug 01 2019(Updated: )
cPanel before 11.54.0.4 allows arbitrary file-read and file-write operations via scripts/fixmailboxpath (SEC-80).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cpanel Cpanel | >=11.48.0.5<11.48.5.2 | |
Cpanel Cpanel | >=11.50.0.4<11.50.4.3 | |
Cpanel Cpanel | >=11.51.9999.98<11.52.2.4 | |
Cpanel Cpanel | >=11.54.0.0<11.54.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-10847 is a high-severity vulnerability due to its potential for arbitrary file-read and file-write operations.
To mitigate CVE-2016-10847, upgrade to cPanel version 11.54.0.4 or later.
CVE-2016-10847 allows unauthorized access to sensitive files and the ability to write arbitrary files, which can lead to data compromise.
cPanel versions before 11.54.0.4, including 11.48.x, 11.50.x, 11.51.x, and 11.52.x, are vulnerable to CVE-2016-10847.
Any cPanel users running versions prior to 11.54.0.4 may be affected by CVE-2016-10847.