CVE-2017-18409: Input Validation
Published Aug 2, 2019
·Updated
In cPanel before 67.9999.103, the backup interface could return a backup archive with all MySQL databases (SEC-283).
Affected Software
6 affected components
Cpanel Cpanel>=55.9999.61<56.0.52
Cpanel Cpanel>=59.9999.58<60.0.48
Cpanel Cpanel>=61.9999.55<62.0.30
Cpanel Cpanel>=63.9999.74<64.0.40
Cpanel Cpanel>=65.9999.38<66.0.23
Cpanel Cpanel>=67.9999.64<67.9999.103
Event History
Aug 2, 2019
CVE Published
via MITRE·01:48 PM
Data Sourced
via MITRE·01:48 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18409?
CVE-2017-18409 is considered a critical vulnerability due to the exposure of MySQL database backups.
2
How do I fix CVE-2017-18409?
To fix CVE-2017-18409, upgrade to cPanel version 67.9999.103 or higher.
3
What are the consequences of CVE-2017-18409?
The consequences of CVE-2017-18409 include unauthorized access to sensitive MySQL database information.
4
Which versions of cPanel are affected by CVE-2017-18409?
CVE-2017-18409 affects cPanel versions prior to 67.9999.103.
5
How can I verify if my cPanel installation is vulnerable to CVE-2017-18409?
You can verify if your cPanel installation is vulnerable by checking if your version is earlier than 67.9999.103.