vendor:
cPanel
by:
ninjashell
8.8
CVSS
HIGH
CSRF
352
CWE
Product Name: cPanel
Affected Version From: 11.25
Affected Version To: 11.25
Patch Exists: YES
Related CWE: N/A
CPE: cpanel:cpanel
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2011
cPanel < 11.25 CSRF - Add php script
cPanel versions below and excluding 11.25, are vulnerable to CSRF which leads to uploading a PHP script of the attackers liking. If you have turned off security tokens and referrer security check, no matter what version you are using, you are vulnerable as well.
Mitigation:
All cPanel versions starting from 11.25 and above have two in-built security features to prevent such attacks - security tokens and referrer security check. This means that if you are a cpanel client, you should update your software.