CVE-2018-20929: Medium severity cpanel vulnerability
Published Aug 1, 2019
·Updated
cPanel before 70.0.23 allows an open redirect via the /unprotected/redirect.html endpoint (SEC-392).
Affected Software
3 affected components
Cpanel Cpanel>=61.9999.55<62.0.42
Cpanel Cpanel>=67.9999.64<68.0.33
Cpanel Cpanel>=69.9999.122<70.0.23
Event History
Aug 1, 2019
CVE Published
via MITRE·03:20 PM
Data Sourced
via MITRE·03:20 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20929?
CVE-2018-20929 has been rated as a medium severity open redirect vulnerability.
2
How do I fix CVE-2018-20929?
To fix CVE-2018-20929, upgrade cPanel to version 70.0.23 or later.
3
What impact does CVE-2018-20929 have on cPanel users?
CVE-2018-20929 allows attackers to redirect users to malicious sites, compromising user trust.
4
Which versions of cPanel are affected by CVE-2018-20929?
CVE-2018-20929 affects cPanel versions prior to 70.0.23, including 61.x, 62.x, and 68.x versions.
5
Is there a workaround for CVE-2018-20929 until I can update cPanel?
Disabling the open redirect capability in the cPanel settings can serve as a temporary workaround for CVE-2018-20929.