Remote Code Execution Vulnerability in cPanel by cPanel, Inc.
CVE-2020-10120

7.2HIGH

Key Information:

Vendor

Cpanel

Status
Vendor
CVE Published:
17 March 2020

What is CVE-2020-10120?

A remote code execution vulnerability exists in cPanel prior to version 84.0.20. This flaw allows resellers to execute arbitrary code with root privileges via the cpsrvd rsync shell. Due to insufficient validation of inputs in the communication lines, improper commands can be sent, potentially leading to unauthorized control over the system. Users of cPanel should upgrade to the latest version to mitigate risks associated with this vulnerability.

References

EPSS Score

5% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.