cPanel before 55.9999.141 allows attackers to bypass Two Factor Authentication via DNS clustering requests (SEC-93).
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cpanel | Cpanel | 11.50.0.4 (including) | 11.50.5.2 (excluding) |
Cpanel | Cpanel | 11.52.0.5 (including) | 11.52.4.1 (excluding) |
Cpanel | Cpanel | 11.54.0.0 (including) | 11.54.0.20 (excluding) |