HTTP Smuggling in cPanel allows potential leak of credentials.
SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials.
Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints.
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
An issue was discovered in cPanel 110 through 132. A directory traversal vulnerability within the Team Manager API allows for overwrite of an arbitrary file. This can allow for privilege escalation to the root user.
The WHM Locale Upload feature in cPanel before 98.0.1 allows XXE attacks (SEC-585).
The WHM Locale Upload feature in cPanel before 98.0.1 allows unserialization attacks (SEC-585).
In cPanel before 98.0.1, /scripts/cpanconfig performs unsafe operations on files (SEC-589).
In cPanel before 96.0.13, scripts/fix-cpanel-perl mishandles the creation of temporary files (SEC-586).
In cPanel before 96.0.13, fixcpanelperl lacks verification of the integrity of downloads (SEC-587).
In cPanel before 96.0.13, scripts/fix-cpanel-perl does not properly restrict the overwriting of files (SEC-588).
In cPanel before 96.0.8, weak permissions on web stats can lead to information disclosure (SEC-584).
In cPanel before 57.9999.54, /scripts/enablefileprotect exposed TTYs (SEC-117).
In cPanel before 57.9999.54, /scripts/unsuspendacct exposed TTYs (SEC-116).
In cPanel before 57.9999.54, /scripts/maildirconverter exposed a TTY to an unprivileged process (SEC-115).
In cPanel before 57.9999.54, /scripts/checkinfopages exposed a TTY to an unprivileged process (SEC-114).
In cPanel before 57.9999.54, /scripts/addpop and /scripts/delpop exposed TTYs (SEC-113).
cPanel before 57.9999.54 allows certain denial-of-service outcomes via /scripts/killpvhost (SEC-112).
cPanel before 57.9999.54 allows self XSS on the Paper Lantern Landing Page (SEC-110).
cPanel before 57.9999.54 allows demo accounts to execute arbitrary code via ajaxmaketextsyntaxutil.pl (SEC-109).
The SQLite journal feature in cPanel before 57.9999.54 allows arbitrary file-overwrite operations during Horde Restore (SEC-58).
cPanel before 57.9999.105 allows newline injection via LOC records (CPANEL-6923).
cPanel before 58.0.4 allows code execution in the context of other user accounts through the PHP CGI handler (SEC-142).
cPanel before 58.0.4 has improper session handling for shared users (SEC-139).