CVE-2018-20905: Medium severity cpanel vulnerability
Published Aug 1, 2019
·Updated
cPanel before 71.9980.37 allows attackers to make API calls that bypass the backup feature restriction (SEC-429).
Affected Software
4 affected components
Cpanel Cpanel>=61.9999.55<62.0.47
Cpanel Cpanel>=67.9999.64<68.0.39
Cpanel Cpanel>=69.9999.122<70.0.43
Cpanel Cpanel>=71.9980.30<71.9980.37
Event History
Aug 1, 2019
CVE Published
via MITRE·02:25 PM
Data Sourced
via MITRE·02:25 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20905?
CVE-2018-20905 has a severity rating that can potentially allow unauthorized access to API functions.
2
How do I fix CVE-2018-20905?
To fix CVE-2018-20905, update cPanel to the latest version above 71.9980.37.
3
What versions are affected by CVE-2018-20905?
CVE-2018-20905 affects cPanel versions prior to 71.9980.37, including several versions from 61.9999.55 up to 70.0.43.
4
What impact does CVE-2018-20905 have on cPanel users?
CVE-2018-20905 allows attackers to make unauthorized API calls that can bypass backup feature restrictions, potentially compromising data.
5
Is there a workaround for CVE-2018-20905?
There is no documented workaround for CVE-2018-20905; the only solution is to upgrade to an unaffected version.