CVE-2017-18414: High severity cpanel vulnerability
Published Aug 2, 2019
·Updated
cPanel before 67.9999.103 allows an open redirect in /unprotected/redirect.html (SEC-300).
Affected Software
6 affected components
Cpanel Cpanel<56.0.52
Cpanel Cpanel>=57.9999.48<60.0.48
Cpanel Cpanel>=61.9999.55<62.0.30
Cpanel Cpanel>=62.0.31<64.0.40
Cpanel Cpanel>=64.0.42<66.0.23
Cpanel Cpanel>=66.0.24<67.9999.103
Event History
Aug 2, 2019
CVE Published
via MITRE·01:52 PM
Data Sourced
via MITRE·01:52 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18414?
CVE-2017-18414 is categorized as a medium severity vulnerability due to its potential for open redirection.
2
How do I fix CVE-2017-18414?
To fix CVE-2017-18414, update your cPanel installation to version 67.9999.103 or later.
3
What impact does CVE-2017-18414 have?
CVE-2017-18414 allows attackers to exploit open redirects, which can lead to phishing attacks or unauthorized access.
4
Which versions of cPanel are affected by CVE-2017-18414?
CVE-2017-18414 affects cPanel versions prior to 67.9999.103, specifically versions up to 66.0.24.
5
Is there a workaround for CVE-2017-18414?
There is no specific workaround for CVE-2017-18414 other than applying the available update to mitigate the risk.