CVE-2017-5614: Medium severity Cpanel Cpanel vulnerability
Published Mar 3, 2017
·Updated
Open redirect vulnerability in cgiemail and cgiecho allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the (1) success or (2) failure parameter.
Affected Software
4 affected components
Cpanel Cpanel>=11.54.0.0<11.54.0.36
Cpanel Cpanel>=55.9999.61<56.0.43
Cpanel Cpanel>=57.9999.48<58.0.43
Cpanel Cpanel>=59.9999.58<60.0.35
Event History
Mar 3, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-5614?
CVE-2017-5614 has been rated as a medium severity vulnerability.
2
How do I fix CVE-2017-5614?
To fix CVE-2017-5614, you should update cPanel to the latest version that is not affected by this vulnerability.
3
What types of attacks are possible with CVE-2017-5614?
CVE-2017-5614 allows attackers to carry out phishing attacks by redirecting users to arbitrary websites.
4
In which versions of cPanel is CVE-2017-5614 found?
CVE-2017-5614 affects cPanel versions between 11.54.0.0 and 11.54.0.36, and other specified versions.
5
What is the impact of CVE-2017-5614?
The impact of CVE-2017-5614 can lead to unauthorized redirects and potential data theft through phishing.