CVE-2018-20926: Malicious File Upload
Published Aug 1, 2019
·Updated
cPanel before 70.0.23 allows local privilege escalation via the WHM Locale XML Upload interface (SEC-380).
Affected Software
3 affected components
Cpanel Cpanel>=61.9999.55<62.0.42
Cpanel Cpanel>=67.9999.64<68.0.33
Cpanel Cpanel>=69.9999.122<70.0.23
Event History
Aug 1, 2019
CVE Published
via MITRE·03:18 PM
Data Sourced
via MITRE·03:18 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20926?
CVE-2018-20926 has been classified as a local privilege escalation vulnerability, which can have significant impacts on affected systems.
2
How do I fix CVE-2018-20926?
To resolve CVE-2018-20926, upgrade to cPanel version 70.0.23 or later.
3
Which versions of cPanel are affected by CVE-2018-20926?
CVE-2018-20926 affects cPanel versions prior to 70.0.23, including versions 61.9999.55 to 62.0.42 and 67.9999.64 to 68.0.33.
4
What is the impact of exploiting CVE-2018-20926?
Exploitation of CVE-2018-20926 can allow attackers to gain elevated privileges on the system.
5
Is it necessary to reboot the server after patching CVE-2018-20926?
Typically, a server reboot is not necessary after upgrading to a secure version to address CVE-2018-20926.