Interestana
Home/News/cPanel Flaw Grants Root Access, Server Control
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

cPanel Flaw Grants Root Access, Server Control

cPanel Flaw Grants Root Access, Server Control

A critical security vulnerability within cPanel's CalDAV and CardDAV service, disclosed on September 22, enabled any user with a cPanel hosting account to execute code with root privileges, thereby achieving complete control over the server. This significant flaw, identified by cPanel itself, posed a substantial risk to the integrity and security of hosted environments. Root access is the highest level of administrative privilege on a Unix-like operating system, granting unrestricted permissions to modify any file, access any data, and control any process on the server. Gaining this level of access allows an attacker to install malware, steal sensitive data, disrupt services, or use the server for malicious purposes, such as launching further attacks.

In addition to the CalDAV/CardDAV vulnerability, cPanel also addressed a separate bug found in its WP Toolkit plugin. This plugin is a widely used tool designed to simplify the installation and management of WordPress websites for hosting account holders. The WP Toolkit flaw permitted an account holder to alter databases belonging to other accounts hosted on the same server. This could lead to data corruption, unauthorized access to other users' website content, or the defacement of websites. The ability to modify another account's database without authorization represents a serious breach of data isolation and security within a shared hosting environment.

In response to these discovered vulnerabilities, cPanel has proactively released updated versions of its software that address both issues. The company has made fixed versions available to its customers, emphasizing the importance of immediate application to mitigate the risks. While cPanel did not specify the exact versions affected or the timeline of the vulnerabilities' existence prior to discovery, the disclosure and subsequent patching indicate a swift response to protect its user base. The company's internal reporting of the flaws highlights a commitment to transparency and security within their platform. Users are strongly advised to update their cPanel installations to the latest patched versions to safeguard their servers and hosted accounts from potential exploitation.

These vulnerabilities underscore the ongoing challenges in maintaining robust security for web hosting platforms, especially those managing numerous accounts and complex software stacks. Shared hosting environments, by their nature, require stringent security measures to prevent lateral movement and unauthorized access between individual accounts. The existence of such flaws, even when quickly rectified, serves as a reminder for both hosting providers and end-users to remain vigilant about security updates and best practices. The potential impact of these bugs, ranging from full server compromise to unauthorized database manipulation, emphasizes the critical need for continuous security auditing and rapid patching of discovered vulnerabilities in all software infrastructure.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next