cPanel before 68.0.15 allows code execution in the context of the root account because of weak permissions on incremental backups (SEC-322).
Weaknesses in this category are related to improper assignment or handling of permissions.
Link | Tags |
---|---|
https://documentation.cpanel.net/display/CL/68+Change+Log | release notes product |
https://news.cpanel.com/cpanel-tsr-2017-0006-full-disclosure/ | vendor advisory |