CVE-2020-10115: Critical severity cpanel vulnerability
Published Mar 17, 2020
·Updated
cPanel before 84.0.20, when PowerDNS is used, allows arbitrary code execution as root via dnsadmin. (SEC-537).
Affected Software
2 affected components
Cpanel Cpanel>=77.9999.110<78.0.45
Cpanel Cpanel>=83.9999.115<84.0.20
Event History
Mar 17, 2020
CVE Published
via MITRE·02:35 PM
Data Sourced
via MITRE·02:35 PM
Description
Frequently Asked Questions
1
What is CVE-2020-10115?
CVE-2020-10115 is a vulnerability in cPanel before version 84.0.20 when PowerDNS is used, allowing arbitrary code execution as root via dnsadmin.
2
How severe is CVE-2020-10115?
The severity of CVE-2020-10115 is critical with a CVSS score of 7.2.
3
What software versions are affected by CVE-2020-10115?
CVE-2020-10115 affects cPanel versions between 77.9999.110 and 78.0.45, as well as versions between 83.9999.115 and 84.0.20.
4
How can I fix CVE-2020-10115?
To fix CVE-2020-10115, you should update cPanel to version 84.0.20 or later.
5
Where can I find more information about CVE-2020-10115?
You can find more information about CVE-2020-10115 in the cPanel Change Log on the official cPanel documentation website.