CVE-2018-20896: Code Injection
Published Aug 1, 2019
·Updated
cPanel before 71.9980.37 allows code injection in the WHM cPAddons interface (SEC-394).
Affected Software
4 affected components
Cpanel Cpanel>=61.9999.55<62.0.47
Cpanel Cpanel>=67.9999.64<68.0.39
Cpanel Cpanel>=69.9999.122<70.0.43
Cpanel Cpanel>=71.9980.30<71.9980.37
Event History
Aug 1, 2019
CVE Published
via MITRE·01:52 PM
Data Sourced
via MITRE·01:52 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20896?
CVE-2018-20896 is classified as a high severity vulnerability due to its potential for code injection.
2
How do I fix CVE-2018-20896?
To fix CVE-2018-20896, you should upgrade your cPanel to a version that is 71.9980.37 or later.
3
What versions of cPanel are affected by CVE-2018-20896?
CVE-2018-20896 affects cPanel versions prior to 71.9980.37, including versions 61.9999.55 to 62.0.47, 67.9999.64 to 68.0.39, and 69.9999.122 to 70.0.43.
4
What is the nature of the vulnerability described in CVE-2018-20896?
The vulnerability in CVE-2018-20896 pertains to code injection in the WHM cPAddons interface.
5
Is there a known exploit for CVE-2018-20896?
There is a potential for exploitation of CVE-2018-20896, which allows an attacker to execute arbitrary code via the affected interface.