CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
cPanel before 80.0.5 uses world-readable permissions for the Queueprocd log (SEC-494).
cPanel before 80.0.5 allows unsafe file operations in the context of the root account via the fetch_ssl_certificates_for_fqdns API (SEC-489).
cPanel before 80.0.5 allows local code execution in the context of a different cPanel account because of insecure cpphp execution (SEC-486).
cPanel before 80.0.22 allows remote code execution by a demo account because of incorrect URI dispatching (SEC-501).
cPanel before 82.0.2 does not properly enforce Reseller package creation ACLs (SEC-514).
cPanel before 82.0.2 has stored XSS in the WHM Modify Account interface (SEC-512).
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'.
cPanel before 82.0.2 allows local users to discover the MySQL root password (SEC-510).
cPanel before 82.0.2 allows unauthenticated file creation because Exim log parsing is mishandled (SEC-507).
cPanel before 82.0.2 has Self XSS in the cPanel and webmail master templates (SEC-506).
