First published: Tue Mar 17 2020(Updated: )
cPanel before 84.0.20, when PowerDNS is used, allows arbitrary code execution as root via dnsadmin. (SEC-537).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cpanel Cpanel | >=77.9999.110<78.0.45 | |
Cpanel Cpanel | >=83.9999.115<84.0.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10115 is a vulnerability in cPanel before version 84.0.20 when PowerDNS is used, allowing arbitrary code execution as root via dnsadmin.
The severity of CVE-2020-10115 is critical with a CVSS score of 7.2.
CVE-2020-10115 affects cPanel versions between 77.9999.110 and 78.0.45, as well as versions between 83.9999.115 and 84.0.20.
To fix CVE-2020-10115, you should update cPanel to version 84.0.20 or later.
You can find more information about CVE-2020-10115 in the cPanel Change Log on the official cPanel documentation website.