New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control
Overview
A new vulnerability in cPanel's CalDAV and CardDAV service allows anyone with a cPanel hosting account to execute code with root privileges, giving them full control of the server. This serious flaw was disclosed on September 22 and affects users who rely on cPanel for their web hosting services. Additionally, a separate issue in the WP Toolkit plugin enables account holders to modify databases belonging to other users, raising further security concerns. cPanel has responded by releasing fixed versions to address both vulnerabilities, underscoring the need for users to update their systems promptly to prevent potential exploitation.
Key Takeaways
- Affected Systems: cPanel, CalDAV, CardDAV, WP Toolkit
- Action Required: cPanel has released fixed versions for both vulnerabilities.
- Timeline: Disclosed on September 22, 2023
Original Article Summary
A flaw in cPanel's CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take "full control of the server," the company said on September 22. A second bug in the WP Toolkit plugin, used to install and manage WordPress sites, allows an account holder to change databases that belong to other accounts. cPanel has released fixed versions for both,
Impact
cPanel, CalDAV, CardDAV, WP Toolkit
Exploitation Status
The exploitation status is currently unknown. Monitor vendor advisories and security bulletins for updates.
Timeline
Disclosed on September 22, 2023
Remediation
cPanel has released fixed versions for both vulnerabilities.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Vulnerability, Update.