CVE-2017-18478: Infoleak
Published Aug 5, 2019
·Updated
In cPanel before 62.0.4 incorrect ACL checks could occur in xml-api for Rearrange Account actions (SEC-207).
Affected Software
5 affected components
Cpanel Cpanel>=11.54.0.0<11.54.0.36
Cpanel Cpanel>=55.9999.61<56.0.43
Cpanel Cpanel>=57.9999.48<58.0.43
Cpanel Cpanel>=59.9999.58<60.0.35
Cpanel Cpanel>=61.9999.55<62.0.4
Event History
Aug 5, 2019
CVE Published
via MITRE·12:47 PM
Data Sourced
via MITRE·12:47 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18478?
The severity of CVE-2017-18478 is classified as medium due to incorrect ACL checks that may allow unauthorized access.
2
How do I fix CVE-2017-18478?
To fix CVE-2017-18478, upgrade your cPanel installation to a version later than 62.0.4.
3
What software versions are affected by CVE-2017-18478?
CVE-2017-18478 affects cPanel versions before 62.0.4, and also several versions between 55.9999.61 and 61.9999.55.
4
What actions are impacted by CVE-2017-18478?
CVE-2017-18478 impacts the Rearrange Account actions within the cPanel xml-api.
5
Are there any workarounds for CVE-2017-18478?
There are no official workarounds for CVE-2017-18478; the recommended action is to update to a secure version.