Arbitrary file disclosure in cPanel - #VU4873
Published: January 18, 2017
Vulnerability details
The vulnerability allows a remote attacker to read arbitrary files on the system.
The vulnerability exists due to an error when processing valiases for users. A remote authenticated user can create valias, which includes other files, and read them with privileges of Exim system user.
Successful exploitation of the vulnerability may allow an attacker to read arbitrary files on the system.
Affected software
Remediation
62.0.4
60.0.35
58.0.43