CVE-2017-18474: Infoleak
Published Aug 5, 2019
·Updated
cPanel before 62.0.4 allows arbitrary file-read operations via Exim valiases (SEC-201).
Affected Software
5 affected components
Cpanel Cpanel>=11.54.0.0<11.54.0.36
Cpanel Cpanel>=55.9999.61<56.0.43
Cpanel Cpanel>=57.9999.48<58.0.43
Cpanel Cpanel>=59.9999.58<60.0.35
Cpanel Cpanel>=61.9999.55<62.0.4
Event History
Aug 5, 2019
CVE Published
via MITRE·12:44 PM
Data Sourced
via MITRE·12:44 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18474?
CVE-2017-18474 is classified as a medium severity vulnerability allowing arbitrary file-read operations.
2
How do I fix CVE-2017-18474?
To fix CVE-2017-18474, update your cPanel software to version 62.0.4 or later.
3
What software is affected by CVE-2017-18474?
CVE-2017-18474 affects cPanel versions before 62.0.4, including versions 11.54.0.36 and earlier.
4
What type of vulnerability is CVE-2017-18474?
CVE-2017-18474 is a file read vulnerability that can lead to unauthorized access to sensitive information.
5
Can CVE-2017-18474 be exploited remotely?
Yes, CVE-2017-18474 can be exploited remotely by attackers through Exim valiases.