CVE-2017-18411: Input Validation
Published Aug 2, 2019
·Updated
The "addon domain conversion" feature in cPanel before 67.9999.103 can copy all MySQL databases to the new account (SEC-285).
Affected Software
6 affected components
Cpanel Cpanel>=55.9999.61<56.0.52
Cpanel Cpanel>=59.9999.58<60.0.48
Cpanel Cpanel>=61.9999.55<62.0.30
Cpanel Cpanel>=64.0.0<64.0.40
Cpanel Cpanel>=65.9999.38<66.0.23
Cpanel Cpanel>=67.9999.64<67.9999.103
Event History
Aug 2, 2019
CVE Published
via MITRE·01:50 PM
Data Sourced
via MITRE·01:50 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18411?
CVE-2017-18411 has been classified as a medium severity vulnerability due to potential exposure of MySQL databases.
2
How do I fix CVE-2017-18411?
To fix CVE-2017-18411, update your cPanel installation to version 67.9999.103 or later.
3
What systems are affected by CVE-2017-18411?
CVE-2017-18411 affects multiple versions of cPanel prior to 67.9999.103.
4
What are the potential risks of CVE-2017-18411?
The potential risks of CVE-2017-18411 include unauthorized access to MySQL databases, which can lead to data breaches.
5
Is CVE-2017-18411 a remote code execution vulnerability?
No, CVE-2017-18411 is not a remote code execution vulnerability; it primarily involves database exposure risks.