CVE-2020-12784: Medium severity cpanel vulnerability
Published May 11, 2020
·Updated
cPanel before 86.0.14 allows remote attackers to trigger a bandwidth suspension via mail log strings (SEC-505).
Affected Software
3 affected components
Cpanel Cpanel>=11.78.0.1<11.78.0.47
Cpanel Cpanel>=11.84.0.0<11.84.0.22
Cpanel Cpanel>=11.86.0.1<11.86.0.14
Event History
May 11, 2020
CVE Published
via MITRE·03:49 PM
Data Sourced
via MITRE·03:49 PM
Description
Frequently Asked Questions
1
What is CVE-2020-12784?
CVE-2020-12784 is a vulnerability in cPanel before version 86.0.14 that allows remote attackers to trigger a bandwidth suspension via mail log strings (SEC-505).
2
How severe is CVE-2020-12784?
CVE-2020-12784 has a severity rating of medium with a CVSS score of 5.3.
3
How can I fix CVE-2020-12784?
To fix CVE-2020-12784, you need to update cPanel to version 86.0.14 or later.
4
Where can I find more information about CVE-2020-12784?
You can find more information about CVE-2020-12784 in the cPanel Change Log and the cPanel TSR-2020-0002 Full Disclosure.