CVE-2018-20907: Medium severity cpanel vulnerability
cPanel before 71.9980.37 does not enforce the Mime::listhotlinks API feature restriction (SEC-432).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-20907?
The severity of CVE-2018-20907 has not been explicitly rated, but it can lead to potential security risks due to improper access controls.
How do I fix CVE-2018-20907?
To fix CVE-2018-20907, upgrade to cPanel version 72.0.0 or later where the issue has been addressed.
What versions of cPanel are affected by CVE-2018-20907?
CVE-2018-20907 affects cPanel versions prior to 71.9980.37, including versions between 61.9999.55 and 62.0.47, 67.9999.64 and 68.0.39, and 69.9999.122 and 70.0.43.
Are there known exploits for CVE-2018-20907?
As of now, there are no widely reported exploits for CVE-2018-20907, but the vulnerability could be leveraged if left unaddressed.
What is the impact of CVE-2018-20907 on cPanel?
The impact of CVE-2018-20907 is that it may allow unauthorized access to the Mime::list_hotlinks API feature, compromising security controls.