First published: Fri Mar 03 2017(Updated: )
Open redirect vulnerability in cgiemail and cgiecho allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the (1) success or (2) failure parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cpanel Cpanel | >=11.54.0.0<11.54.0.36 | |
Cpanel Cpanel | >=55.9999.61<56.0.43 | |
Cpanel Cpanel | >=57.9999.48<58.0.43 | |
Cpanel Cpanel | >=59.9999.58<60.0.35 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-5614 has been rated as a medium severity vulnerability.
To fix CVE-2017-5614, you should update cPanel to the latest version that is not affected by this vulnerability.
CVE-2017-5614 allows attackers to carry out phishing attacks by redirecting users to arbitrary websites.
CVE-2017-5614 affects cPanel versions between 11.54.0.0 and 11.54.0.36, and other specified versions.
The impact of CVE-2017-5614 can lead to unauthorized redirects and potential data theft through phishing.