The SSL certificate-storage feature in cPanel before 78.0.18 allows unsafe file operations in the context of the root account (SEC-477).
NVD-CWE-noinfo
CVE-2019-14400
cPanel before 78.0.18 allows local users to escalate to root access because of userdata cache misparsing (SEC-479).
CVE-2019-14401
cPanel before 78.0.18 allows code execution via an addforward API1 call (SEC-480).
CVE-2019-14402
cPanel before 78.0.18 unsafely determines terminal capabilities by using infocmp (SEC-481).
CVE-2019-14404
cPanel before 78.0.18 allows certain file-read operations in the context of the root account via the Exim virtual_user_spam router (SEC-484).
CVE-2019-14405
cPanel before 78.0.18 allows demo accounts to execute code via securitypolicy.cg (SEC-487).
