cPanel TSR-2020-0002 Full Disclosure | cPanel Newsroom
SEC-505
Summary
Bandwidth suspensions can be triggered remotely via mail log strings.
Security Rating
cPanel has assigned this vulnerability a CVSSv3 score of 5.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
Description
The regular expression patterns used to match bandwidth log lines in the mail log were not properly anchored. This allowed remote attackers to generate fake bandwidth consumption…
View On WordPress













