CVE-2017-6513: Critical severity Softaculous WHMCS Reseller Module vulnerability
The WHMCS Reseller Module V2 2.0.2 in Softaculous Virtualizor before 2.9.1.0 does not verify the user correctly, which allows remote authenticated users to control other virtual machines managed by Virtualizor by accessing a modified URL.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6513?
CVE-2017-6513 is considered a critical vulnerability due to its potential to allow unauthorized control over virtual machines.
How do I fix CVE-2017-6513?
To fix CVE-2017-6513, users should upgrade to Softaculous WHMCS Reseller Module version 2.0.3 or later.
Who is affected by CVE-2017-6513?
CVE-2017-6513 affects users of Softaculous WHMCS Reseller Module version 2.0.2 and earlier, as well as Softaculous Virtualizor versions up to 2.9.0.6.
What type of attack can exploit CVE-2017-6513?
CVE-2017-6513 can be exploited by remote authenticated users who can manipulate URLs to gain access to other virtual machines.
Is there a workaround for CVE-2017-6513?
There is no official workaround for CVE-2017-6513; updating to the latest version is the recommended solution.