CVE-2018-20925: Malicious File Upload
Published Aug 1, 2019
·Updated
cPanel before 70.0.23 allows local privilege escalation via the WHM Legacy Language File Upload interface (SEC-379).
Affected Software
3 affected components
Cpanel Cpanel>=61.9999.55<62.0.42
Cpanel Cpanel>=67.9999.64<68.0.33
Cpanel Cpanel>=69.9999.122<70.0.23
Event History
Aug 1, 2019
CVE Published
via MITRE·03:18 PM
Data Sourced
via MITRE·03:18 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20925?
CVE-2018-20925 has been classified as a local privilege escalation vulnerability that may allow unauthorized users to gain elevated privileges.
2
How do I fix CVE-2018-20925?
To mitigate CVE-2018-20925, upgrade cPanel to version 70.0.23 or later.
3
What versions of cPanel are affected by CVE-2018-20925?
CVE-2018-20925 affects cPanel versions below 70.0.23, specifically those in the ranges of 61.9999.55 to 62.0.42, 67.9999.64 to 68.0.33, and 69.9999.122 to 70.0.23.
4
Can CVE-2018-20925 be exploited remotely?
CVE-2018-20925 is a local privilege escalation vulnerability, meaning it requires local access to exploit.
5
What impact does CVE-2018-20925 have on system security?
Exploitation of CVE-2018-20925 can compromise the integrity of the system by allowing malicious users to gain elevated privileges.