First published: Thu Aug 01 2019(Updated: )
cPanel before 74.0.0 allows file modification in the context of the root account because of incorrect HTTP authentication (SEC-424).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cpanel Cpanel | >=69.9999.122<70.0.53 | |
Cpanel Cpanel | >=71.9980.30<72.0.10 | |
Cpanel Cpanel | >=73.9980.0<74.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-20888 is considered to have a high severity due to the potential for unauthorized file modification by the root account.
To fix CVE-2018-20888, update your cPanel installation to version 74.0.0 or higher.
CVE-2018-20888 affects cPanel versions below 74.0.0, specifically versions 69.x.x, 70.x.x, 71.x.x, and 72.x.x.
Exploiting CVE-2018-20888 can allow an attacker to modify files on the server with root privileges, compromising system integrity.
There are no known workarounds for CVE-2018-20888; upgrading to the latest version is the recommended action.