First published: Tue Mar 17 2020(Updated: )
cPanel before 84.0.20 allows a demo account to achieve code execution via PassengerApps APIs (SEC-546).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cpanel Cpanel | >=77.9999.110<78.0.45 | |
Cpanel Cpanel | >=83.9999.115<84.0.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10121 is a vulnerability in cPanel before version 84.0.20 that allows a demo account to achieve code execution via PassengerApps APIs (SEC-546).
The severity of vulnerability CVE-2020-10121 is rated as critical with a severity value of 9.8.
cPanel versions between 77.9999.110 and 78.0.45, and versions between 83.9999.115 and 84.0.20 are affected by CVE-2020-10121.
To fix CVE-2020-10121, you need to update your cPanel installation to version 84.0.20 or later.
You can find more information about CVE-2020-10121 in the cPanel documentation change log: [here](https://documentation.cpanel.net/display/CL/84+Change+Log).