CVE-2018-20888: Medium severity cpanel vulnerability
Published Aug 1, 2019
·Updated
cPanel before 74.0.0 allows file modification in the context of the root account because of incorrect HTTP authentication (SEC-424).
Affected Software
3 affected components
Cpanel Cpanel>=69.9999.122<70.0.53
Cpanel Cpanel>=71.9980.30<72.0.10
Cpanel Cpanel>=73.9980.0<74.0.0
Event History
Aug 1, 2019
CVE Published
via MITRE·01:04 PM
Data Sourced
via MITRE·01:04 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20888?
CVE-2018-20888 is considered to have a high severity due to the potential for unauthorized file modification by the root account.
2
How do I fix CVE-2018-20888?
To fix CVE-2018-20888, update your cPanel installation to version 74.0.0 or higher.
3
What versions of cPanel are affected by CVE-2018-20888?
CVE-2018-20888 affects cPanel versions below 74.0.0, specifically versions 69.x.x, 70.x.x, 71.x.x, and 72.x.x.
4
What are the consequences of exploiting CVE-2018-20888?
Exploiting CVE-2018-20888 can allow an attacker to modify files on the server with root privileges, compromising system integrity.
5
Is there a workaround for CVE-2018-20888?
There are no known workarounds for CVE-2018-20888; upgrading to the latest version is the recommended action.