CVE-2018-20931: Code Injection
Published Aug 1, 2019
·Updated
cPanel before 70.0.23 allows demo accounts to execute code via the Landing Page (SEC-405).
Affected Software
3 affected components
Cpanel Cpanel>=61.9999.55<62.0.42
Cpanel Cpanel>=67.9999.64<68.0.33
Cpanel Cpanel>=69.9999.122<70.0.23
Event History
Aug 1, 2019
CVE Published
via MITRE·03:47 PM
Data Sourced
via MITRE·03:47 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20931?
CVE-2018-20931 is classified as a high severity vulnerability that allows demo accounts to execute code.
2
How do I fix CVE-2018-20931?
To fix CVE-2018-20931, you must upgrade to cPanel version 70.0.23 or later.
3
What versions of cPanel are affected by CVE-2018-20931?
CVE-2018-20931 affects cPanel versions prior to 70.0.23, including versions 61.9999.55 to 62.0.42 and 67.9999.64 to 68.0.33.
4
What does CVE-2018-20931 exploit?
CVE-2018-20931 exploits a vulnerability in cPanel allowing code execution through demo accounts on the Landing Page.
5
Who is affected by CVE-2018-20931?
All users of affected cPanel versions who utilize demo accounts are at risk due to CVE-2018-20931.