CVE-2017-18416: SQL Injection
Published Aug 2, 2019
·Updated
cPanel before 67.9999.103 allows arbitrary file-overwrite operations during a Roundcube SQLite schema update (SEC-303).
Affected Software
6 affected components
Cpanel Cpanel<56.0.52
Cpanel Cpanel>=57.9999.48<60.0.48
Cpanel Cpanel>=61.9999.55<62.0.30
Cpanel Cpanel>=62.0.31<64.0.40
Cpanel Cpanel>=64.0.42<66.0.23
Cpanel Cpanel>=66.0.24<67.9999.103
Event History
Aug 2, 2019
CVE Published
via MITRE·01:53 PM
Data Sourced
via MITRE·01:53 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18416?
CVE-2017-18416 is classified as a medium severity vulnerability due to its potential for unauthorized file manipulation.
2
How do I fix CVE-2017-18416?
To mitigate CVE-2017-18416, upgrade cPanel to version 68.0 or later.
3
What systems are affected by CVE-2017-18416?
CVE-2017-18416 affects cPanel versions prior to 67.9999.103.
4
What kind of attack can exploit CVE-2017-18416?
CVE-2017-18416 allows for arbitrary file overwrite operations, which can lead to unauthorized access or data loss.
5
Are there any known exploits for CVE-2017-18416?
Yes, CVE-2017-18416 can be potentially exploited by attackers during a Roundcube SQLite schema update.