First published: Thu Aug 01 2019(Updated: )
cPanel before 71.9980.37 allows code injection in the WHM cPAddons interface (SEC-394).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cpanel Cpanel | >=61.9999.55<62.0.47 | |
Cpanel Cpanel | >=67.9999.64<68.0.39 | |
Cpanel Cpanel | >=69.9999.122<70.0.43 | |
Cpanel Cpanel | >=71.9980.30<71.9980.37 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-20896 is classified as a high severity vulnerability due to its potential for code injection.
To fix CVE-2018-20896, you should upgrade your cPanel to a version that is 71.9980.37 or later.
CVE-2018-20896 affects cPanel versions prior to 71.9980.37, including versions 61.9999.55 to 62.0.47, 67.9999.64 to 68.0.39, and 69.9999.122 to 70.0.43.
The vulnerability in CVE-2018-20896 pertains to code injection in the WHM cPAddons interface.
There is a potential for exploitation of CVE-2018-20896, which allows an attacker to execute arbitrary code via the affected interface.