Security research firm Fortbridge has released a report claiming to have discovered “multiple vulnerabilities in cPanel/WHM”.
The report states:
“Our team has found multiple vulnerabilities in cPanel/WHM during a black-box pentest, the most important one being a privilege escalation via stored XSS. Whilst disclosing these bugs to the cPanel/WHM team, we discovered the pentested cPanel account was a reseller account with the permission to edit locales, thus this is not a default setting. The XSS vulnerability which we will present is considered a feature, and it was not fixed. We will show how this “feature” can be abused to escalate privileges to root, together with the rest of our findings.”
The report is quite detailed and shows in-depth the path they take to conduct the attack.
So what do you think – is this indeed a “feature” or is it a genuine bug? cPanel has disputed the severity of this issue.
Related Posts:
VisualWebTechnologies: Cheap cPanel and DirectAdmin - As Cheap as $6/Year!
"Wait! Don't End Black Friday Without Posting This Offer!" - Win Authority has Cheap cPanel Shared H...
CYBER MONDAY: VerpexWeb has Cheap cPanel Hosting for Under $7/Year! DirectAdmin for Only $3.50/Year...
BLACK FRIDAY: Get cPanel or DirectAdmin Shared Hosting for Under $7 per Year from eWallHost!
BLACK FRIDAY: VisualWebTechnologies has Shared Hosting for $2/Year Plus Deals on Cheap cPanel and Re...
WHMCS and cPanel Prices Going Up By... 5%? 10%? Keep Guessing...
- Elcro Digital: 4GB VPS for $5.27/Month in Dallas, With Powerful DDoS Protection and a Five-Nines SLA! - February 16, 2025
- $600,000 in Overdue Rent: Read the QuadraNet Eviction Complaints - February 15, 2025
- Wherever You Are In The World, Have Some Hosting Fun with Host4Fun! 17 Locations in North America and Europe!! - February 15, 2025
Leave a Reply