Code execution due to faulty file extension dispatching - Cpanel
Table of Contents
Published on July 21st, 2020 cPanel has released a new cPanel security advisory for all public updates. These updates address security concerns with the cPanel & WHM product. This advisory is concerned with code execution due to faulty file extension dispatching in Cpanel and is currently available to all customers via the standard update system.
Aligning to industry best practices and standards of providing the best services to you, we publish security advisories that are designed to provide timely information to all our esteemed customers.
cPanel and WHM’s cpsrvd daemon did not verify that some file extensions matched the actual file that would handle a request before dispatching the request to the file extension’s handler.
In a default configuration of cPanel & WHM, this allowed webmail accounts to execute code on the server.
Also read,
How to identify and Prevent Common Security Threats to Your Website
Solution
This issue is resolved in the following builds:
11.88.0.13
11.86.0.24
We at Hostripples always encourage our customers to pursue the best practices of security to keep their systems updated, protected, and patched against recognized vulnerabilities.
Official references and security advisories:
https://news.cpanel.com/cpanel-tsr-2020-0004-full-disclosure/
If you have any queries regarding the patching/updates on Hostripples Networks infrastructure, you may write an email to support@hostripples.com
YouTube SEO Secrets That Actually Work in 2026 YouTube SEO 2026 YouTube SEO Secrets That Actually Work in 2026 If…
Live video commerce is transforming how small businesses sell products online. Instead of relying only on static product pages or…
Digital marketing directly impacts revenue, brand positioning, and customer acquisition cost. Choosing the wrong agency can result in wasted budgets,…
The release of WordPress 6.9 introduces meaningful enhancements focused on performance, block editing flexibility, design precision, and long-term scalability. This…
The wp-content/uploads folder is the core storage location for media files in WordPress. Every image, PDF, video, or document uploaded…