A flaw in cPanel's CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take "full control of the server," the company said on September 22.
A second bug in the WP Toolkit plugin, used to install and manage WordPress sites, allows an account holder to change databases that belong to other accounts.
cPanel has released fixed versions for both, along with a fix for a third flaw in the same service, which stores each account's calendars and contacts. That third flaw lets a local user on the server read other accounts' calendar events and contacts, but not change them or gain root access.
cPanel lists no requirements for the root flaw other than having an account. On a shared server where a hosting provider sells accounts to the public, that means any customer could use it. So could anyone who gets hold of a customer's login.
The WP Toolkit bug is in how the plugin handles commands that create databases. cPanel says only that a logged-in cPanel user could "perform database modifications in other accounts."
It does not say what changes are possible, whether data from other accounts can also be read, or whether the user needs access to WP Toolkit itself.
WP Toolkit is also available for Plesk, another hosting control panel from the same company, WebPros. cPanel has not said whether the Plesk version is affected.
None of the three advisories mentions exploitation or gives a way to check whether a server was attacked before it was updated.
Source link







