CVE-2017-18437: Medium severity cpanel vulnerability
Published Aug 2, 2019
·Updated
cPanel before 64.0.21 allows a Webmail account to execute code via forwarders (SEC-240).
Affected Software
5 affected components
Cpanel Cpanel>=55.9999.61<56.0.49
Cpanel Cpanel>=57.9999.48<58.0.49
Cpanel Cpanel>=59.9999.58<60.0.43
Cpanel Cpanel>=61.9999.55<62.0.24
Cpanel Cpanel>=63.9999.74<64.0.21
Event History
Aug 2, 2019
CVE Published
via MITRE·04:13 PM
Data Sourced
via MITRE·04:13 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18437?
CVE-2017-18437 is considered a critical vulnerability due to its potential to allow arbitrary code execution.
2
How do I fix CVE-2017-18437?
To fix CVE-2017-18437, users should upgrade cPanel to version 64.0.21 or later.
3
What versions of cPanel are affected by CVE-2017-18437?
CVE-2017-18437 affects cPanel versions prior to 64.0.21, including specific versions from 55.x.x to 64.x.x.
4
Can CVE-2017-18437 be exploited remotely?
Yes, CVE-2017-18437 can be exploited remotely by attackers targeting webmail accounts.
5
What actions should I take if my cPanel installation is vulnerable to CVE-2017-18437?
If your cPanel installation is vulnerable to CVE-2017-18437, it is crucial to upgrade to the patched version immediately to mitigate the risk.