cPanel before 64.0.21 allows attackers to read a user's crontab file during a short time interval upon a cPAddon upgrade (SEC-257).
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://documentation.cpanel.net/display/CL/64+Change+Log | release notes product |
https://news.cpanel.com/cpanel-tsr-2017-0003-full-disclosure/ | vendor advisory |