First published: Tue Mar 17 2020(Updated: )
cPanel before 84.0.20 allows attackers to bypass intended restrictions on features and demo accounts via WebDisk UAPI calls (SEC-541).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cpanel Cpanel | >=77.9999.110<78.0.45 | |
Cpanel Cpanel | >=83.9999.115<84.0.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10116 is a vulnerability in cPanel before version 84.0.20 that allows attackers to bypass intended restrictions on features and demo accounts.
CVE-2020-10116 allows attackers to bypass intended restrictions on features and demo accounts through WebDisk UAPI calls in cPanel before version 84.0.20.
The severity of CVE-2020-10116 is medium, with a CVSS score of 5.3.
CVE-2020-10116 affects cPanel versions between 77.9999.110 and 84.0.20.
To fix CVE-2020-10116, you should update your cPanel installation to version 84.0.20 or later.