cPanel flaw lets a hosting account run code as root and take over the server
cPanel disclosed on September 22 a flaw in its CalDAV and CardDAV service that lets any hosting account holder run code as root and take full control of the server. A second bug in the WP Toolkit plugin allows an account holder to alter databases belonging to other accounts. Fixed versions have been released for both.
- CalDAV/CardDAV flaw allows code execution as root
- WP Toolkit bug lets accounts modify other accounts' databases
- cPanel released fixed versions for both vulnerabilities
Read next
Security