CVE-2018-20882: Input Validation
Published Aug 1, 2019
·Updated
cPanel before 74.0.8 allows arbitrary file-write operations in the context of the root account during WHM Force Password Change (SEC-447).
Affected Software
2 affected components
Cpanel Cpanel>=69.9999.122<70.0.57
Cpanel Cpanel>=73.9980.0<74.0.8
Event History
Aug 1, 2019
CVE Published
via MITRE·12:55 PM
Data Sourced
via MITRE·12:55 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20882?
CVE-2018-20882 is rated as a high-severity vulnerability due to its ability to allow arbitrary file-write operations as the root account.
2
How do I fix CVE-2018-20882?
To fix CVE-2018-20882, upgrade cPanel to version 74.0.8 or higher.
3
What type of systems are affected by CVE-2018-20882?
CVE-2018-20882 affects cPanel versions prior to 74.0.8 and versions between 69.9999.122 and 70.0.57.
4
What can an attacker do with CVE-2018-20882?
An attacker exploiting CVE-2018-20882 can perform arbitrary file-write operations, potentially compromising the system.
5
Is CVE-2018-20882 exploitable remotely?
Yes, CVE-2018-20882 can be exploited remotely if the vulnerabilities are present in the cPanel installations.