CVE-2018-20934: Medium severity cpanel vulnerability
Published Aug 1, 2019
·Updated
cPanel before 70.0.23 does not prevent e-mail account suspensions from being applied to unowned accounts (SEC-411).
Affected Software
3 affected components
Cpanel Cpanel>=61.9999.55<62.0.42
Cpanel Cpanel>=67.9999.64<68.0.33
Cpanel Cpanel>=69.9999.122<70.0.23
Event History
Aug 1, 2019
CVE Published
via MITRE·03:50 PM
Data Sourced
via MITRE·03:50 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20934?
CVE-2018-20934 is considered a medium severity vulnerability.
2
How do I fix CVE-2018-20934?
To fix CVE-2018-20934, you should update cPanel to version 70.0.23 or later.
3
What impact does CVE-2018-20934 have on cPanel security?
CVE-2018-20934 allows e-mail account suspensions to be improperly applied to accounts that are not owned, potentially leading to unauthorized account access.
4
Which versions of cPanel are affected by CVE-2018-20934?
CVE-2018-20934 affects cPanel versions prior to 70.0.23, including 61.9999.55 to 62.0.42 and 67.9999.64 to 68.0.33.
5
Is there a workaround for CVE-2018-20934?
There are no known workarounds for CVE-2018-20934; the recommended action is to update to the latest version of cPanel.