CVE-2020-10120: Critical severity cpanel vulnerability
Published Mar 17, 2020
·Updated
cPanel before 84.0.20 allows resellers to achieve remote code execution as root via a cpsrvd rsync shell (SEC-545).
Affected Software
1 affected component
Cpanel Cpanel<84.0.20
Event History
Mar 17, 2020
CVE Published
via MITRE·02:39 PM
Data Sourced
via MITRE·02:39 PM
Description
Frequently Asked Questions
1
What is CVE-2020-10120?
CVE-2020-10120 is a vulnerability in cPanel that allows resellers to achieve remote code execution as root via a cpsrvd rsync shell.
2
How severe is CVE-2020-10120?
CVE-2020-10120 is considered critical with a severity rating of 7.2.
3
Which version of cPanel is affected by CVE-2020-10120?
cPanel versions up to and excluding 84.0.20 are affected by CVE-2020-10120.
4
How can resellers exploit CVE-2020-10120?
Resellers can exploit CVE-2020-10120 by using a cpsrvd rsync shell to achieve remote code execution as root.
5
Is there a fix available for CVE-2020-10120?
Yes, the fix for CVE-2020-10120 is included in cPanel version 84.0.20.