Remote Code Execution Vulnerability in cPanel by cPanel, Inc.
CVE-2020-10120
7.2HIGH
Summary
A remote code execution vulnerability exists in cPanel prior to version 84.0.20. This flaw allows resellers to execute arbitrary code with root privileges via the cpsrvd rsync shell. Due to insufficient validation of inputs in the communication lines, improper commands can be sent, potentially leading to unauthorized control over the system. Users of cPanel should upgrade to the latest version to mitigate risks associated with this vulnerability.
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved