cPanel의 취약점으로 이메일 권한을 가진 계정이 서버의 root 권한으로 코드 실행 가능.
cPanel은 단일 호스팅 계정이 전체 서버를 제어할 수 있게 하는 취약점을 수정했습니다. 이메일 관련 특권을 가진 인증된 계정 사용자는 EmailTrack을 통해 서버에 원하는 파일을 생성하고, 이를 통해 root 사용자로서 코드를 실행할 수 있습니다. cPanel은 9월 8일에 이들의 조치를 발표했으며, 모든 지원되는 버전의 cPanel 및 WHM이 영향을 받습니다.
cPanel flaw allows a mail-privileged hosting account to run code as root.
cPanel has patched a flaw that lets a single hosting account gain control over an entire server. An authenticated user with mail-related privileges can create arbitrary files on the server through EmailTrack, allowing them to execute code as the root user. cPanel published this advisory on September 8, indicating that every supported version of cPanel and WHM is affected.