CVE-2019-14392: High severity cpanel vulnerability
Published Jul 30, 2019
·Updated
cPanel before 80.0.22 allows remote code execution by a demo account because of incorrect URI dispatching (SEC-501).
Affected Software
1 affected component
Cpanel Cpanel<80.0.22
Event History
Jul 30, 2019
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-14392?
CVE-2019-14392 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2019-14392?
To fix CVE-2019-14392, upgrade cPanel to version 80.0.22 or later.
3
Which versions of cPanel are affected by CVE-2019-14392?
CVE-2019-14392 affects cPanel versions prior to 80.0.22.
4
Who can exploit CVE-2019-14392?
A demo account can exploit CVE-2019-14392 to perform remote code execution.
5
What type of vulnerability is CVE-2019-14392?
CVE-2019-14392 is a remote code execution vulnerability due to incorrect URI dispatching.