CVE-2018-20947

MEDIUM

Cpanel < 62.0.39 - Exposure to Wrong Actor

Title source: rule

Description

cPanel before 68.0.27 allows certain file-write operations via the telnetcrt script (SEC-356).

Scores

CVSS v3 5.5
EPSS 0.0007
EPSS Percentile 20.7%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Classification

CWE
CWE-668
Status published

Affected Products (1)

cpanel/cpanel < 62.0.39

Timeline

Published Aug 01, 2019
Tracked Since Feb 18, 2026