cPanel before 11.54.0.4 allows arbitrary code execution because of an unsafe @INC path (SEC-46).
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
Link | Tags |
---|---|
https://documentation.cpanel.net/display/CL/54+Change+Log | release notes vendor advisory |