CVE-2017-18433: Input Validation
Published Aug 2, 2019
·Updated
cPanel before 64.0.21 allows code execution by webmail and demo accounts via a storefilter API call (SEC-236).
Affected Software
5 affected components
Cpanel Cpanel>=55.9999.61<56.0.49
Cpanel Cpanel>=57.9999.48<58.0.49
Cpanel Cpanel>=59.9999.58<60.0.43
Cpanel Cpanel>=61.9999.55<62.0.24
Cpanel Cpanel>=63.9999.74<64.0.21
Event History
Aug 2, 2019
CVE Published
via MITRE·03:58 PM
Data Sourced
via MITRE·03:58 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18433?
CVE-2017-18433 has a high severity level due to its potential for code execution.
2
How do I fix CVE-2017-18433?
To fix CVE-2017-18433, upgrade to cPanel version 64.0.21 or later.
3
What types of accounts are affected by CVE-2017-18433?
CVE-2017-18433 affects webmail and demo accounts.
4
What impact does CVE-2017-18433 have on cPanel users?
CVE-2017-18433 allows unauthorized code execution, posing significant security risks to affected cPanel installations.
5
Which versions of cPanel are vulnerable to CVE-2017-18433?
Versions of cPanel prior to 64.0.21, specifically those between 55.9999.61 and 64.0.20, are vulnerable to CVE-2017-18433.