CVE-2019-20491: Medium severity cpanel vulnerability
Published Mar 16, 2020
·Updated
cPanel before 82.0.18 allows attackers to leverage virtual mail accounts in order to bypass account suspensions (SEC-508).
Affected Software
3 affected components
Cpanel Cpanel>=77.9999.110<78.0.43
Cpanel Cpanel>=81.9999.242<82.0.18
Cpanel Cpanel>=83.9999.115<84.0.10
Event History
Mar 16, 2020
CVE Published
via MITRE·08:13 PM
Data Sourced
via MITRE·08:13 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-20491?
CVE-2019-20491 has a severity rating that suggests it can be exploited to bypass account suspensions, potentially allowing unauthorized access.
2
How do I fix CVE-2019-20491?
To fix CVE-2019-20491, upgrade to cPanel version 82.0.18 or later.
3
What versions of cPanel are affected by CVE-2019-20491?
CVE-2019-20491 affects cPanel versions prior to 82.0.18, as well as specific earlier versions such as 77.9999.110 and up to 81.9999.242.
4
What consequences can occur if CVE-2019-20491 is exploited?
If exploited, CVE-2019-20491 may allow attackers to use virtual mail accounts to access suspended accounts, raising security risks.
5
Is CVE-2019-20491 a known issue in the cPanel community?
Yes, CVE-2019-20491 is documented and recognized within the cPanel community as a vulnerability that warrants immediate attention.