Security Advisory: cPanel and WP Squared
-
security
A local user's .forward file can trigger unsafe string expansion in Exim's redirect router, allowing command injection under certain pipe transport configurations.
-
security
A privilege escalation vulnerability exists in cPanel & WHM's database management functionality.
-
security
A vulnerability in the cPanel web server allows manipulation of cpsrvd responses under limited conditions.
-
fixed
Patched versions are: 11.110.0.137, 11.126.0.78, 11.134.0.48, 11.136.0.32, 138.1.6 (WP2)
-
resolution
Update to the latest patched version:For WHM cPanel Servers
amslicensecp --update-cpanelFor WP Squared Serversamslicensewp2 --update-wp2