CVE Vulnerabilities

CVE-2016-10803

Improper Neutralization of CRLF Sequences ('CRLF Injection')

Published: Aug 07, 2019 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

cPanel before 57.9999.105 allows newline injection via LOC records (CPANEL-6923).

Weakness

The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.

Affected Software

NameVendorStart VersionEnd Version
CpanelCpanel57.9999.48 (including)57.9999.105 (excluding)

Potential Mitigations

References