Vulnerabilities > Cpanel > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-08-01 CVE-2018-20931 Code Injection vulnerability in Cpanel
cPanel before 70.0.23 allows demo accounts to execute code via the Landing Page (SEC-405).
network
low complexity
cpanel CWE-94
6.3
2019-08-01 CVE-2018-20930 Improper Access Control vulnerability in Cpanel
cPanel before 70.0.23 allows .htaccess restrictions bypass when Htaccess Optimization is enabled (SEC-401).
network
low complexity
cpanel CWE-284
6.5
2019-08-01 CVE-2018-20929 Open Redirect vulnerability in Cpanel
cPanel before 70.0.23 allows an open redirect via the /unprotected/redirect.html endpoint (SEC-392).
network
low complexity
cpanel CWE-601
6.1
2019-08-01 CVE-2018-20928 Cross-site Scripting vulnerability in Cpanel
cPanel before 70.0.23 allows stored XSS via the cpaddons vendor interface (SEC-391).
network
low complexity
cpanel CWE-79
6.1
2019-08-01 CVE-2018-20926 Unrestricted Upload of File with Dangerous Type vulnerability in Cpanel
cPanel before 70.0.23 allows local privilege escalation via the WHM Locale XML Upload interface (SEC-380).
local
low complexity
cpanel CWE-434
6.7
2019-08-01 CVE-2018-20925 Unrestricted Upload of File with Dangerous Type vulnerability in Cpanel
cPanel before 70.0.23 allows local privilege escalation via the WHM Legacy Language File Upload interface (SEC-379).
local
low complexity
cpanel CWE-434
6.7
2019-08-01 CVE-2018-20924 Improper Authentication vulnerability in Cpanel
cPanel before 70.0.23 allows arbitrary file-read and file-unlink operations via WHM style uploads (SEC-378).
network
low complexity
cpanel CWE-287
5.5
2019-08-01 CVE-2016-10849 Command Injection vulnerability in Cpanel
cPanel before 11.54.0.4 allows certain file-chmod operations in scripts/secureit (SEC-82).
network
low complexity
cpanel CWE-77
6.5
2019-08-01 CVE-2016-10844 Information Exposure vulnerability in Cpanel
The chcpass script in cPanel before 11.54.0.4 reveals a password hash (SEC-77).
network
low complexity
cpanel CWE-200
6.5
2019-08-01 CVE-2016-10842 Improper Input Validation vulnerability in Cpanel
cPanel before 11.54.0.4 allows certain file-read operations in bin/setup_global_spam_filter.pl (SEC-74).
network
low complexity
cpanel CWE-20
6.5