4.3
CVSSv2

CVE-2008-2071

Published: 12/05/2008 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site request forgery (CSRF) vulnerabilities in the WHM interface 11.15.0 for cPanel 11.18 prior to 11.18.4 and 11.22 prior to 11.22.3 allow remote malicious users to perform unauthorized actions as cPanel administrators via requests to cpanel/whm/webmail and other unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

cpanel cpanel 11.18

cpanel cpanel 11.22

cpanel cpanel 11.18.3

cpanel cpanel 11.18.1

cpanel cpanel 11.22.1

cpanel cpanel 11.22.2

cpanel cpanel 11.18.2

Exploits

cPanel versions below 11184 and 11223 suffer from cross site scripting and cross site request forgery vulnerabilities ...