CVE-2017-18482: Input Validation
Published Aug 5, 2019
·Updated
cPanel before 62.0.4 allows resellers to use the WHM enqueuetransferitem API for queueing non-rearrange modules (SEC-213).
Affected Software
5 affected components
Cpanel Cpanel>=11.54.0.0<11.54.0.36
Cpanel Cpanel>=55.9999.61<56.0.43
Cpanel Cpanel>=57.9999.48<58.0.43
Cpanel Cpanel>=59.9999.58<60.0.35
Cpanel Cpanel>=61.9999.55<62.0.4
Event History
Aug 5, 2019
CVE Published
via MITRE·12:50 PM
Data Sourced
via MITRE·12:50 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18482?
CVE-2017-18482 is considered a medium severity vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2017-18482?
To fix CVE-2017-18482, update your cPanel installation to version 62.0.4 or later.
3
Who is affected by CVE-2017-18482?
CVE-2017-18482 affects cPanel versions before 62.0.4, particularly resellers utilizing the WHM enqueue_transfer_item API.
4
What impact does CVE-2017-18482 have on my cPanel?
The impact of CVE-2017-18482 allows resellers to queue non-rearrange modules, potentially leading to unauthorized access.
5
When was CVE-2017-18482 disclosed?
CVE-2017-18482 was disclosed in December 2017, coinciding with the release of cPanel version 62.0.4.