A serious vulnerability in cPanel's CalDAV and CardDAV services has been discovered, allowing any user with a cPanel hosting account to execute code with root privileges and potentially take full control of the server. This flaw poses a significant risk, particularly for shared server environments where multiple customers have access. Additionally, a bug in the WP Toolkit plugin, which is widely used for managing WordPress sites, allows users to manipulate databases belonging to other accounts. cPanel has responded by releasing updated versions to address these vulnerabilities, as well as a third issue that enables unauthorized reading of calendar events and contacts from other accounts. Although no temporary workaround is available for those unable to immediately update, cPanel has provided specific update instructions for both the cPanel & WHM system and the WP Toolkit. The vulnerabilities were identified by researcher Ali Mustafa, also known as rz1027, who has a track record of discovering security flaws in cPanel and Plesk. As of now, there is no evidence of these exploits being used in the wild, and they are not listed in CISA's Known Exploited Vulnerabilities catalog. However, immediate action is advised to mitigate potential risks.
Critical cPanel Vulnerabilities Expose Servers to Root-Level Attacks
cPanel CalDAV/CardDAV flaw allows any hosting account to execute code as root and fully compromise servers.
Executive Summary
PremiumActionable Insights
PremiumOriginal source
thehackernews.com

