CVE-2017-18460: Input Validation
Published Aug 2, 2019
·Updated
cPanel before 62.0.17 allows arbitrary code execution during automatic SSL installation (SEC-221).
Affected Software
2 affected components
Cpanel Cpanel>=59.9999.58<60.0.39
Cpanel Cpanel>=61.9999.55<62.0.17
Event History
Aug 2, 2019
CVE Published
via MITRE·04:32 PM
Data Sourced
via MITRE·04:32 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18460?
CVE-2017-18460 has a high severity rating due to the potential for arbitrary code execution.
2
How do I fix CVE-2017-18460?
To fix CVE-2017-18460, update your cPanel installation to version 62.0.17 or later.
3
What versions of cPanel are affected by CVE-2017-18460?
CVE-2017-18460 affects cPanel versions before 62.0.17, including versions 59.9999.58 to 60.0.39 and 61.9999.55 to 62.0.16.
4
Is CVE-2017-18460 a widespread vulnerability?
Yes, CVE-2017-18460 is considered widespread as it impacts multiple cPanel versions used by many web hosting providers.
5
What are the risks of not addressing CVE-2017-18460?
Not addressing CVE-2017-18460 could lead to unauthorized access and control over the affected server due to arbitrary code execution capabilities.