A chmod call in the cPanel Nova plugin's Cpanel::Nova::Connector follows symlinks, allowing setting root permissions on arbitrary system files or directories. That can cause DoS or local privilege escalation when an authenticated cPanel user places a symlink at a user-controlled legacy Nova path under their home directory.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| WebPros | WP Squared | >= 11.136.1.0, < 11.136.1.10CNA affecteddefault unaffected | |
| WebPros | CPanel (CloudLinux 6, CentOS 6) | >= 11.110.0.0, < 11.110.0.116CNA affecteddefault unaffected | |
| WebPros | CPanel | >= 11.102.0.0, < 11.102.0.41, >= 11.110.0.0, < 11.110.0.117, >= 11.118.0.0, < 11.118.0.66, >= 11.124.0.0, < 11.124.0.37, >= 11.126.0.0, < 11.126.0.58, >= 11.130.0.0, < 11.130.0.22, >= 11.132.0.0, < 11.132.0.31, >= 11.134.0.0, < 11.134.0.25, >= 11.136.0.0, < 11.136.0.9, >= 11.86.0.0, < 11.86.0.43, >= 11.94.0.0, < 11.94.0.30CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.