#VU4873 Arbitrary file disclosure in cPanel
Published: January 18, 2017
cPanel
cPanel, Inc
Description
The vulnerability allows a remote attacker to read arbitrary files on the system.
The vulnerability exists due to an error when processing valiases for users. A remote authenticated user can create valias, which includes other files, and read them with privileges of Exim system user.
Successful exploitation of the vulnerability may allow an attacker to read arbitrary files on the system.
Remediation
62.0.4
60.0.35
58.0.43