cPanel 9.4.1-RELEASE-64 follows hard links, which allows...
Moderate severity
Unreviewed
Published
Apr 29, 2022
to the GitHub Advisory Database
•
Updated Jan 26, 2024
Description
Published by the National Vulnerability Database
Oct 18, 2004
Published to the GitHub Advisory Database
Apr 29, 2022
Last updated
Jan 26, 2024
cPanel 9.4.1-RELEASE-64 follows hard links, which allows local users to (1) read arbitrary files via the backup feature or (2) chown arbitrary files via the .htaccess file when Front Page extensions are enabled or disabled.
References