CVE-2018-20924: High severity cpanel vulnerability
Published Aug 1, 2019
·Updated
cPanel before 70.0.23 allows arbitrary file-read and file-unlink operations via WHM style uploads (SEC-378).
Affected Software
3 affected components
Cpanel Cpanel>=61.9999.55<62.0.42
Cpanel Cpanel>=67.9999.64<68.0.33
Cpanel Cpanel>=69.9999.122<70.0.23
Event History
Aug 1, 2019
CVE Published
via MITRE·03:17 PM
Data Sourced
via MITRE·03:17 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20924?
CVE-2018-20924 is classified as a critical vulnerability due to its potential for arbitrary file-read and file-unlink operations.
2
How do I fix CVE-2018-20924?
To fix CVE-2018-20924, upgrade your cPanel installation to version 70.0.23 or later.
3
What types of operations are affected by CVE-2018-20924?
CVE-2018-20924 allows for arbitrary file-read and file-unlink operations via WHM style uploads.
4
Which versions of cPanel are vulnerable to CVE-2018-20924?
cPanel versions from 61.9999.55 to 62.0.42, 67.9999.64 to 68.0.33, and 69.9999.122 to 70.0.23 are vulnerable.
5
What should I do if I cannot upgrade cPanel to mitigate CVE-2018-20924?
If an upgrade is not possible, implement strict access controls and monitor file upload activities to reduce risks associated with CVE-2018-20924.