CVE-2019-14398: High severity cpanel vulnerability
Published Jul 30, 2019
·Updated
cPanel before 80.0.5 allows demo accounts to execute arbitrary code via ajaxmaketextsyntaxutil.pl (SEC-498).
Affected Software
1 affected component
Cpanel Cpanel<80.0.5
Event History
Jul 30, 2019
CVE Published
via MITRE·02:06 PM
Data Sourced
via MITRE·02:06 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-14398?
CVE-2019-14398 has a medium severity rating as it allows unauthorized code execution in demo accounts.
2
How do I fix CVE-2019-14398?
To fix CVE-2019-14398, upgrade cPanel to version 80.0.5 or later.
3
Who is affected by CVE-2019-14398?
CVE-2019-14398 affects users of cPanel versions prior to 80.0.5, specifically those with demo accounts.
4
What does CVE-2019-14398 exploit?
CVE-2019-14398 exploits a vulnerability in the ajax_maketext_syntax_util.pl file within cPanel.
5
When was CVE-2019-14398 disclosed?
CVE-2019-14398 was disclosed in 2019, following the release of cPanel version 80.0.5.