Lotu Radar About · RSS

New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

The Hacker News Cybersecurity Score 7/10

Summary

cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there, run code as the root user. cPanel published the advisory on September 8 and says every supported version of cPanel and WHM is affected.

SecurityThreat Intel

Lotu Radar provides attributed news summaries and links to the original publisher. Full reporting and copyright remain with the source.