HomeSecuritySecurity researchers discovered a bug in the cPanel software

Security researchers discovered a bug in cPanel software

Some security researchers discovered a major security flaw in cPanel, a popular software suite used by web hosting companies to manage their clients' websites.

The bug, discovered by the security researchers at Digital Defense, allows attackers to bypass two-factor authentication (2FA) on cPanel accounts.

These accounts are used by website owners to access and manage their websites and the underlying server settings . Access to these accounts is critical, as once compromised, they give threat actors complete control over a victim's website .

cPanel

On its website, cPanel boasts that its software is currently used by hundreds of web hosting companies to manage more than 70 million domains worldwide.

But in a press release today, Digital Defense says that 2FA in older cPanel & WebHost Manager (WHM) software was vulnerable to brute-force attacks that allowed threat actors to guess URL parameters and bypass 2FA – if 2FA was enabled on an account.

While brute-forcing attacks, in general, usually take hours or days to execute, in this particular case, the attack was executed in just a few minutes, Digital Defense said today.

Also, exploiting this bug requires attackers to have valid credentials of a targeted account.

While this may make some website owners think that the error is not significant, it is actually the opposite, as 2FA solutions were invented to protect against phishing attacks and, as a result, any 2FA bypass such as this error should be treated with the utmost caution.

The good news is that Digital Defense privately reported the bug – which was named SEC-575. Also, the cPanel team released some patches last week.

Website owners who use 2FA when logging into cPanel can see if their web hosting provider has released the update to their cPanel installation by checking the platform.

According to the cPanel security advisory, the 2FA bypass issue has been fixed in the cPanel & WHM software versions 11.92.0.2, 11.90.0.17, and 11.86.0.32.

Users should not disable 2FA for their cPanel accounts due to this error, but instead should ask their web hosting providers to update their cPanel installation to the latest version.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS