CVE-2017-18459: Input Validation
Published Aug 2, 2019
·Updated
cPanel before 62.0.17 allows arbitrary code execution during account modification (SEC-220).
Affected Software
4 affected components
Cpanel Cpanel>=55.9999.61<56.0.46
Cpanel Cpanel>=57.9999.48<58.0.45
Cpanel Cpanel>=59.9999.58<60.0.39
Cpanel Cpanel>=61.9999.55<62.0.17
Event History
Aug 2, 2019
CVE Published
via MITRE·04:31 PM
Data Sourced
via MITRE·04:31 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18459?
CVE-2017-18459 is classified as critical due to the potential for arbitrary code execution.
2
How do I fix CVE-2017-18459?
To fix CVE-2017-18459, update cPanel to version 62.0.17 or later.
3
What versions of cPanel are affected by CVE-2017-18459?
CVE-2017-18459 affects cPanel versions before 62.0.17, as well as several versions from 55.x to 61.x.
4
What type of attack does CVE-2017-18459 allow?
CVE-2017-18459 allows an attacker to execute arbitrary code during account modification.
5
Is CVE-2017-18459 an external or internal threat?
CVE-2017-18459 primarily represents an internal threat since it exploits cPanel's account modification functionality.