Vulnerabilities > Cpanel
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-08-01 | CVE-2018-20918 | Cross-site Scripting vulnerability in Cpanel cPanel before 70.0.23 allows stored XSS in WHM DNS Cluster (SEC-372). | 6.1 |
2019-08-01 | CVE-2018-20917 | Improper Input Validation vulnerability in Cpanel cPanel before 70.0.23 allows any user to disable Solr (SEC-371). | 5.5 |
2019-08-01 | CVE-2018-20916 | Cross-site Scripting vulnerability in Cpanel cPanel before 70.0.23 allows Stored XSS via a WHM Edit MX Entry (SEC-370). | 5.4 |
2019-08-01 | CVE-2018-20915 | Cross-site Scripting vulnerability in Cpanel cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-369). | 5.4 |
2019-08-01 | CVE-2018-20914 | Injection vulnerability in Cpanel In cPanel before 70.0.23, OpenID providers can inject arbitrary data into cPanel session files (SEC-368). | 7.3 |
2019-08-01 | CVE-2018-20913 | Information Exposure vulnerability in Cpanel cPanel before 70.0.23 allows attackers to read the root accesshash via the WHM /cgi/trustclustermaster.cgi (SEC-364). | 4.9 |
2019-08-01 | CVE-2018-20912 | Improper Input Validation vulnerability in Cpanel cPanel before 70.0.23 allows demo accounts to execute code via awstats (SEC-362). | 6.3 |
2019-08-01 | CVE-2018-20911 | Cross-site Scripting vulnerability in Cpanel cPanel before 70.0.23 allows code execution because "." is in @INC during a Perl syntax check of cpaddonsup (SEC-359). | 7.2 |
2019-08-01 | CVE-2018-20910 | Cross-site Scripting vulnerability in Cpanel cPanel before 70.0.23 allows self XSS in the WHM cPAddons showsecurity Interface (SEC-357). | 6.1 |
2019-08-01 | CVE-2018-20909 | Incorrect Permission Assignment for Critical Resource vulnerability in Cpanel cPanel before 70.0.23 allows arbitrary file-chmod operations during legacy incremental backups (SEC-338). | 7.1 |