cPanel before 82.0.18 allows authentication bypass because webmail usernames are processed inconsistently (SEC-499).
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cpanel | Cpanel | 77.9999.110 (including) | 78.0.43 (excluding) |
Cpanel | Cpanel | 81.9999.242 (including) | 82.0.18 (excluding) |
Cpanel | Cpanel | 83.9999.115 (including) | 84.0.10 (excluding) |