CVE-2018-20893: Input Validation
Published Aug 1, 2019
·Updated
cPanel before 74.0.0 allows file-rename operations during account renames (SEC-442).
Affected Software
3 affected components
Cpanel Cpanel>=69.9999.122<70.0.53
Cpanel Cpanel>=71.9980.30<72.0.10
Cpanel Cpanel>=73.9980.0<74.0.0
Event History
Aug 1, 2019
CVE Published
via MITRE·01:10 PM
Data Sourced
via MITRE·01:10 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20893?
CVE-2018-20893 is rated as a high severity vulnerability due to the potential for unauthorized file operations.
2
How do I fix CVE-2018-20893?
To fix CVE-2018-20893, upgrade to cPanel version 74.0.0 or later.
3
What systems are affected by CVE-2018-20893?
CVE-2018-20893 affects cPanel versions below 74.0.0, specifically versions in the 69.x, 71.x, and 72.x series.
4
What is the impact of exploiting CVE-2018-20893?
Exploiting CVE-2018-20893 can allow attackers to perform unauthorized file rename operations during account renames.
5
Was CVE-2018-20893 publicly disclosed?
Yes, CVE-2018-20893 was publicly disclosed as part of a security release from cPanel.