CVE-2017-18442: Command Injection
Published Aug 2, 2019
·Updated
cPanel before 64.0.21 allows demo accounts to execute Cpanel::SPFUI API commands (SEC-246).
Affected Software
5 affected components
Cpanel Cpanel>=55.9999.61<56.0.49
Cpanel Cpanel>=57.9999.48<58.0.49
Cpanel Cpanel>=59.9999.58<60.0.43
Cpanel Cpanel>=61.9999.55<62.0.24
Cpanel Cpanel>=63.9999.74<64.0.21
Event History
Aug 2, 2019
CVE Published
via MITRE·04:18 PM
Data Sourced
via MITRE·04:18 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18442?
CVE-2017-18442 has been classified with a moderate severity due to its potential exploitation by demo accounts.
2
How do I fix CVE-2017-18442?
To mitigate CVE-2017-18442, ensure that cPanel is updated to version 64.0.21 or later.
3
Who is affected by CVE-2017-18442?
CVE-2017-18442 affects cPanel versions prior to 64.0.21, specifically within version ranges from 55 to 64.
4
What does CVE-2017-18442 allow demo accounts to do?
CVE-2017-18442 allows demo accounts to execute Cpanel::SPFUI API commands, which should not be permitted.
5
Is CVE-2017-18442 an API vulnerability?
Yes, CVE-2017-18442 is an API vulnerability that affects the execution permissions within the cPanel environment.