As cited
Copy frozen at (site build).
vulnerabilities
New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root
cPanel has patched a vulnerability affecting all supported versions that allows an authenticated hosting account with mail privileges to create arbitrary files on the server through EmailTrack and execute code as root. The flaw enables a single account holder to gain complete control of the entire server.
Why it matters: Hosting providers and cPanel administrators must prioritize patching immediately, as any customer account with mail privileges can escalate to full server compromise.
- Source published
- First seen by Cybersecurity Tracker