CVE-2018-20906: Medium severity cpanel vulnerability
Published Aug 1, 2019
·Updated
cPanel before 71.9980.37 allows attackers to make API calls that bypass the images feature restriction (SEC-430).
Affected Software
3 affected components
Cpanel Cpanel>=61.9999.55<62.0.47
Cpanel Cpanel>=67.9999.64<68.0.39
Cpanel Cpanel>=69.9999.122<70.0.43
Event History
Aug 1, 2019
CVE Published
via MITRE·02:27 PM
Data Sourced
via MITRE·02:27 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20906?
CVE-2018-20906 is considered a medium severity vulnerability that can lead to unauthorized API access.
2
How do I fix CVE-2018-20906?
To mitigate CVE-2018-20906, upgrade to cPanel version 71.9980.37 or later.
3
What systems are affected by CVE-2018-20906?
CVE-2018-20906 affects cPanel versions prior to 71.9980.37, specifically versions 61.9999.55 to 62.0.47, 67.9999.64 to 68.0.39, and 69.9999.122 to 70.0.43.
4
What kind of attacks can CVE-2018-20906 facilitate?
CVE-2018-20906 allows attackers to bypass restrictions on the images feature through unauthorized API calls.
5
Is there a patch available for CVE-2018-20906?
Yes, a patch for CVE-2018-20906 is included in cPanel version 71.9980.37 and later.