cPanel Vulnerability Allowing Package Modification Bypass by cPanel Inc.
CVE-2020-26109

7.5HIGH

Key Information:

Vendor
Cpanel
Status
Vendor
CVE Published:
25 September 2020

Summary

The vulnerability in cPanel versions prior to 88.0.13 allows malicious actors to bypass a mechanism designed to restrict modifications to packages. This flaw can lead to unauthorized changes that compromise the integrity of the package system and potentially expose sensitive data.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.