New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control

A flaw in cPanel’s CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take “full control of the server,” the company said on September 22.

A second bug in the WP Toolkit plugin, used to install and manage WordPress sites, allows an account holder to change databases that belong to other accounts.

cPanel has released fixed versions for both,

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

When str.lower() is a security vulnerability in Python – Seth Larson

When str.lower() is a security vulnerability in Python – Seth Larson Source: Hacker News

Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth

Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth Security researcher Olivier Laflamme has disclosed two independent root remote code execution (RCE) chains affecting the

Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems Brazilian financial services, retail, and e-commerce organizations have become the target of a financially motivated threat actor dubbed Breeze