CVE-2018-20863: Input Validation
Published Jul 30, 2019
·Updated
cPanel before 76.0.8 allows remote attackers to execute arbitrary code via mailing-list attachments (SEC-452).
Affected Software
1 affected component
Cpanel Cpanel<76.0.8
Event History
Jul 30, 2019
CVE Published
via MITRE·02:20 PM
Data Sourced
via MITRE·02:20 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20863?
CVE-2018-20863 is rated as a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2018-20863?
To fix CVE-2018-20863, upgrade cPanel to version 76.0.8 or later.
3
What type of attack does CVE-2018-20863 allow?
CVE-2018-20863 allows remote attackers to execute arbitrary code via malicious mailing-list attachments.
4
Which versions of cPanel are affected by CVE-2018-20863?
CVE-2018-20863 affects all versions of cPanel prior to 76.0.8.
5
Is there a workaround for CVE-2018-20863?
There is no official workaround for CVE-2018-20863; applying the latest update is strongly recommended for mitigation.