First published: Fri Aug 02 2019(Updated: )
cPanel before 62.0.17 allows arbitrary code execution during automatic SSL installation (SEC-221).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cpanel Cpanel | >=59.9999.58<60.0.39 | |
Cpanel Cpanel | >=61.9999.55<62.0.17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-18460 has a high severity rating due to the potential for arbitrary code execution.
To fix CVE-2017-18460, update your cPanel installation to version 62.0.17 or later.
CVE-2017-18460 affects cPanel versions before 62.0.17, including versions 59.9999.58 to 60.0.39 and 61.9999.55 to 62.0.16.
Yes, CVE-2017-18460 is considered widespread as it impacts multiple cPanel versions used by many web hosting providers.
Not addressing CVE-2017-18460 could lead to unauthorized access and control over the affected server due to arbitrary code execution capabilities.