CVE-2018-20886: Medium severity cpanel vulnerability
Published Aug 1, 2019
·Updated
cPanel before 74.0.0 insecurely stores phpMyAdmin session files (SEC-418).
Affected Software
3 affected components
Cpanel Cpanel>=69.9999.122<70.0.53
Cpanel Cpanel>=71.9980.30<72.0.10
Cpanel Cpanel>=73.9980.0<74.0.0
Event History
Aug 1, 2019
CVE Published
via MITRE·01:01 PM
Data Sourced
via MITRE·01:01 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20886?
CVE-2018-20886 is considered a medium severity vulnerability due to the insecure storage of session files.
2
How do I fix CVE-2018-20886?
To mitigate CVE-2018-20886, update cPanel to version 74.0.0 or later to ensure proper handling of phpMyAdmin session files.
3
What versions of cPanel are affected by CVE-2018-20886?
CVE-2018-20886 affects cPanel versions prior to 74.0.0, including versions from 69.9999.122 to 70.0.53, 71.9980.30 to 72.0.10, and 73.9980.0 to 74.0.0.
4
What is the impact of CVE-2018-20886?
The impact of CVE-2018-20886 allows unauthorized access to phpMyAdmin session files, potentially leading to session hijacking.
5
Is CVE-2018-20886 a local or remote vulnerability?
CVE-2018-20886 is primarily a local vulnerability, as it relies on access to the filesystem where the session files are stored.