CVE Vulnerabilities

CVE-2018-20934

Improperly Implemented Security Check for Standard

Published: Aug 01, 2019 | Modified: Aug 12, 2019
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

cPanel before 70.0.23 does not prevent e-mail account suspensions from being applied to unowned accounts (SEC-411).

Weakness

The product does not implement or incorrectly implements one or more security-relevant checks as specified by the design of a standardized algorithm, protocol, or technique.

Affected Software

Name Vendor Start Version End Version
Cpanel Cpanel 61.9999.55 (including) 62.0.42 (excluding)
Cpanel Cpanel 67.9999.64 (including) 68.0.33 (excluding)
Cpanel Cpanel 69.9999.122 (including) 70.0.23 (excluding)

References