CVE-2017-18421

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
02/08/2019
Last modified:
06/08/2019

Description

cPanel before 66.0.2 allows demo accounts to create databases and users (SEC-271).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* 60.0.3 (including) 60.0.45 (excluding)
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* 62.0.1 (including) 62.0.27 (excluding)
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* 64.0.0 (including) 64.0.33 (excluding)
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* 66.0.1 (including) 66.0.2 (excluding)


References to Advisories, Solutions, and Tools