cPanel before 64.0.21 allows certain file-chmod operations via /scripts/convert_roundcube_mysql2sqlite (SEC-255).
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://documentation.cpanel.net/display/CL/64+Change+Log | release notes vendor advisory |
https://news.cpanel.com/cpanel-tsr-2017-0003-full-disclosure/ | vendor advisory |