CVE-2020-10118: Critical severity cpanel vulnerability
Published Mar 17, 2020
·Updated
cPanel before 84.0.20 allows a demo account to modify files via Branding API calls (SEC-543).
Affected Software
2 affected components
Cpanel Cpanel>=77.9999.110<78.0.45
Cpanel Cpanel>=83.9999.115<84.0.20
Event History
Mar 17, 2020
CVE Published
via MITRE·02:38 PM
Data Sourced
via MITRE·02:38 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-10118.
2
What is the title of the vulnerability?
The title of the vulnerability is 'cPanel before 84.0.20 allows a demo account to modify files via Branding API calls (SEC-543).'
3
What is the severity of CVE-2020-10118?
The severity of CVE-2020-10118 is critical with a severity value of 9.1.
4
How can a demo account modify files in cPanel before version 84.0.20?
A demo account can modify files in cPanel before version 84.0.20 through Branding API calls.
5
Where can I find more information about the vulnerability and its fix?
More information about the vulnerability and its fix can be found in the cPanel Change Log: https://documentation.cpanel.net/display/CL/84+Change+Log