cPanel before 70.0.23 allows arbitrary file-read and file-unlink operations via WHM style uploads (SEC-378).
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cpanel | Cpanel | 61.9999.55 (including) | 62.0.42 (excluding) |
Cpanel | Cpanel | 67.9999.64 (including) | 68.0.33 (excluding) |
Cpanel | Cpanel | 69.9999.122 (including) | 70.0.23 (excluding) |