Open redirect vulnerability in cgiemail and cgiecho allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the (1) success or (2) failure parameter.
cPanel before 55.9999.141 mishandles username-based blocking for PRE requests in cPHulkd (SEC-104).
cPanel before 55.9999.141 allows FTP cPHulk bypass via account name munging (SEC-102).
cPanel before 55.9999.141 allows account-suspension bypass via ftp (SEC-105).
cPanel before 59.9999.145 allows stored XSS in the WHM tailupcp2.cgi interface (SEC-156).
cPanel before 59.9999.145 allows arbitrary file-read operations because of a multipart form processing error (SEC-154).
cPanel before 58.0.4 allows code execution in the context of other user accounts through the PHP CGI handler (SEC-142).
cPanel before 55.9999.141 allows ACL bypass for AppConfig applications via magicrevision (SEC-100).
cPanel before 57.9999.54 allows demo-mode escape via showtemplate.stor (SEC-119).
cPanel before 55.9999.141 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-90).
cPanel before 55.9999.141 does not perform as two-factor authentication check when possessing another account (SEC-101).
cPanel before 58.0.4 allows demo-mode escape via Site Templates and Boxtrapper API calls (SEC-138).
cPanel before 55.9999.141 allows a POP/IMAP cPHulk bypass via account name munging (SEC-107).
cPanel before 55.9999.141 allows arbitrary file-read operations during authentication with caldav (SEC-108).
cPanel before 60.0.25 allows members of the nobody group to read Apache HTTP Server SSL keys (SEC-186).
cPanel before 60.0.25 allows stored XSS during the homedir removal phase of WHM Account termination (SEC-174).
cPanel before 60.0.25 allows self XSS in the alias upload interface (SEC-184).
cPanel before 60.0.25 allows stored XSS in the ftpsessions API (SEC-180).
cPanel before 60.0.25 allows stored XSS in api1listautoresponders (SEC-179).
cPanel before 60.0.25 allows self stored XSS in SSLlistkeys (SEC-182).
cPanel before 60.0.25 allows self XSS in the UIconfirm API (SEC-180).
cPanel before 60.0.25 allows self stored XSS in postgres API1 listdbs (SEC-181).
cPanel before 60.0.25 allows code execution via the cpsrvd 403 error response handler (SEC-191).
cPanel before 60.0.25 allows self XSS in WHM Tweak Settings for autodiscoverhost (SEC-177).
cPanel before 55.9999.141 allows self stored XSS in WHM Edit System Mail Preferences (SEC-96).
The Host Access Control feature in cPanel before 60.0.25 mishandles actionless host.deny entries (SEC-187).
cPanel before 60.0.25 allows self stored XSS in the listftpstable API (SEC-178).
cPanel before 60.0.25 allows attackers to discover file contents during file copy operations (SEC-185).
cPanel before 58.0.4 initially uses weak permissions for Apache HTTP Server log files (SEC-130).
cPanel before 60.0.25 allows file-create and file-chmod operations during ModSecurity Audit logfile processing (SEC-165).