CVE Vulnerabilities

CVE-2016-10803

Improper Neutralization of CRLF Sequences ('CRLF Injection')

Published: Aug 07, 2019 | Modified: Aug 12, 2019
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

cPanel before 57.9999.105 allows newline injection via LOC records (CPANEL-6923).

Weakness

The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.

Affected Software

Name Vendor Start Version End Version
Cpanel Cpanel 57.9999.48 (including) 57.9999.105 (excluding)

Potential Mitigations

References