General-Purpose System Vulnerabilities
Vulnerabilities related to traditional IT systems, servers, and desktop applications.
| CVE ID | Description | Severity | Published | Type |
|---|---|---|---|---|
| CVE-2020-10118 | cPanel before 84.0.20 allows a demo account to modify files via Branding API calls (SEC-543). | Critical (9.1) | 2020-03-17 | General Purpose |
| CVE-2020-10117 | cPanel before 84.0.20 mishandles enforcement of demo checks in the Market UAPI namespace (SEC-542). | Critical (9.1) | 2020-03-17 | General Purpose |
| CVE-2020-10116 | cPanel before 84.0.20 allows attackers to bypass intended restrictions on features and demo accounts via WebDisk UAPI c… | Medium (5.3) | 2020-03-17 | General Purpose |
| CVE-2020-10115 | cPanel before 84.0.20, when PowerDNS is used, allows arbitrary code execution as root via dnsadmin. (SEC-537). | High (7.2) | 2020-03-17 | General Purpose |
| CVE-2020-10114 | cPanel before 84.0.20 allows stored self-XSS via the HTML file editor (SEC-535). | Medium (6.1) | 2020-03-17 | General Purpose |