CVE-2018-20895

HIGH

cPanel 67.9999.64-71.9980.37 - Improper Input Validation

Title source: llm
STIX 2.1

Description

In cPanel before 71.9980.37, API tokens retain ACLs after those ACLs are removed from the corresponding accounts (SEC-393).

References (2)

Core 2

Scores

CVSS v3 7.2
EPSS 0.0050
EPSS Percentile 66.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (1)
cpanel/cpanel 67.9999.64 - 68.0.39
Published Aug 01, 2019
Tracked Since Feb 18, 2026