cPanel before 68.0.27 allows attackers to read the SRS secret via exim.conf (SEC-308).
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
https://documentation.cpanel.net/display/CL/68+Change+Log | release notes vendor advisory |