New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control
A vulnerability in cPanel's CalDAV and CardDAV services, along with a flaw in the WP Toolkit plugin, allows unauthorized users to gain root access to cPanel servers, potentially taking full control. Ali Mustafa, known as rz1027, discovered all three flaws, with cPanel releasing fixes. The flaws could be exploited by anyone with a cPanel account, including those who obtain a customer's login credentials.
A vulnerability in cPanel’s CalDAV and CardDAV services, alongside a flaw in the WP Toolkit plugin, presents a significant security risk, allowing unauthorized users to gain root access to cPanel servers. Ali Mustafa, operating under the pseudonym rz1027, identified all three flaws, with cPanel issuing fixes on September 22nd. The vulnerabilities could be exploited by anyone with a cPanel account, including those who obtain a customer’s login credentials. The CalDAV and CardDAV issues allow an attacker to execute code as root, effectively taking full control of the server. The WP Toolkit flaw enables a user to modify databases belonging to other accounts. cPanel credits all three flaws to Mustafa, who has previously disclosed seven cPanel and Plesk flaws since August 27th, including a September 8th flaw in cPanel’s EmailTrack feature. Plesk addressed two additional flaws on September 10th, related to its Backup Manager and handling of backup headers. cPanel provides separate update instructions for cPanel & WHM and for WP Toolkit. WP Toolkit is installed as its own package, wp-toolkit-cpanel, with its own update. The calendar flaws affect version 120 and later, but cPanel lists fixed builds only for the 134, 136, and 138 release lines and for WP Squared. cPanel offers no temporary workaround for servers that cannot be updated yet. For WP Toolkit, only the manual command is given, and whether automatic updates will install 6.11.3 is not stated.
