CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
cPanel before 74.0.0 allows certain file-read operations via password file caching (SEC-425).
cPanel before 74.0.0 allows file modification in the context of the root account because of incorrect HTTP authentication (SEC-424).
cPanel before 74.0.0 allows SQL injection during database backups (SEC-420).
cPanel before 74.0.0 insecurely stores phpMyAdmin session files (SEC-418).
cPanel before 74.0.0 allows Apache HTTP Server configuration injection because of DocumentRoot variable interpolation (SEC-416).
cPanel before 74.0.0 allows stored XSS in the WHM File Restoration interface (SEC-367).
cPanel before 74.0.8 allows FTP access during account suspension (SEC-449).
cPanel before 74.0.8 allows arbitrary file-write operations in the context of the root account during WHM Force Password Change (SEC-447).
cPanel before 74.0.8 allows self stored XSS on the Security Questions login page (SEC-446).
cPanel before 74.0.8 mishandles account suspension because of an invalid email_accounts.json file (SEC-445).
