First published: Thu Aug 01 2019(Updated: )
cPanel before 70.0.23 allows arbitrary file-read and file-unlink operations via WHM style uploads (SEC-378).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cpanel Cpanel | >=61.9999.55<62.0.42 | |
Cpanel Cpanel | >=67.9999.64<68.0.33 | |
Cpanel Cpanel | >=69.9999.122<70.0.23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-20924 is classified as a critical vulnerability due to its potential for arbitrary file-read and file-unlink operations.
To fix CVE-2018-20924, upgrade your cPanel installation to version 70.0.23 or later.
CVE-2018-20924 allows for arbitrary file-read and file-unlink operations via WHM style uploads.
cPanel versions from 61.9999.55 to 62.0.42, 67.9999.64 to 68.0.33, and 69.9999.122 to 70.0.23 are vulnerable.
If an upgrade is not possible, implement strict access controls and monitor file upload activities to reduce risks associated with CVE-2018-20924.