CVE-2020-26114
cPanel before 90.0.10 allows self XSS via the Cron Jobs interface (SEC-573).
Source: CVE-2020-26114
CVE-2020-26114
cPanel before 90.0.10 allows self XSS via the Cron Jobs interface (SEC-573).
Source: CVE-2020-26114
CVE-2020-26107
cPanel before 88.0.3, upon an upgrade, establishes predictable PowerDNS API keys (SEC-561).
Source: CVE-2020-26107
CVE-2020-26106
cPanel before 88.0.3 has weak permissions (world readable) for the proxy subdomains log file (SEC-558).
Source: CVE-2020-26106
CVE-2020-26109
cPanel before 88.0.13 allows bypass of a protection mechanism that attempted to restrict package modification (SEC-557).
Source: CVE-2020-26109
CVE-2020-26108
cPanel before 88.0.13 mishandles file-extension dispatching, leading to code execution (SEC-488).
Source: CVE-2020-26108
CVE-2020-26110
cPanel before 88.0.13 allows self XSS via DNS Zone Manager DNSSEC interfaces (SEC-564).
Source: CVE-2020-26110
CVE-2020-26113
cPanel before 90.0.10 allows self XSS via WHM Manage API Tokens interfaces (SEC-569).
Source: CVE-2020-26113
CVE-2020-26115
cPanel before 90.0.10 allows self XSS via the Cron Editor interface (SEC-574).
Source: CVE-2020-26115
CVE-2020-26098
cPanel before 88.0.3 mishandles the Exim filter path, leading to remote code execution (SEC-485).
Source: CVE-2020-26098
CVE-2020-26099
cPanel before 88.0.3 allows attackers to bypass the SMTP greylisting protection mechanism (SEC-491).
Source: CVE-2020-26099