CVE-2018-20891: Input Validation
Published Aug 1, 2019
·Updated
cPanel before 74.0.0 allows arbitrary file-read operations during File Restoration (SEC-436).
Affected Software
3 affected components
Cpanel Cpanel>=69.9999.122<70.0.53
Cpanel Cpanel>=71.9980.30<72.0.10
Cpanel Cpanel>=73.9980.0<74.0.0
Event History
Aug 1, 2019
CVE Published
via MITRE·01:08 PM
Data Sourced
via MITRE·01:08 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20891?
CVE-2018-20891 is categorized as a high severity vulnerability due to its potential for arbitrary file-read operations.
2
How do I fix CVE-2018-20891?
To fix CVE-2018-20891, upgrade to cPanel version 74.0.0 or later.
3
What systems are affected by CVE-2018-20891?
CVE-2018-20891 affects cPanel versions before 74.0.0, specifically versions 69.9999.122 to 70.0.53, 71.9980.30 to 72.0.10, and 73.9980.0 to 74.0.0.
4
What type of vulnerability is CVE-2018-20891?
CVE-2018-20891 is an arbitrary file-read vulnerability that occurs during the File Restoration process.
5
Can CVE-2018-20891 lead to data leakage?
Yes, CVE-2018-20891 can potentially lead to data leakage as it allows unauthorized access to arbitrary files.