CVE-2017-18421: cPanel
Low severity, CVSS 3.3. EPSS: 0.3% chance of exploitation in the next 30 days.
cPanel before 66.0.2 allows demo accounts to create databases and users (SEC-271).
Affected products
- cPanel cPanel: from 60.0.3, before 60.0.45 (fixed in 60.0.45); from 62.0.1, before 62.0.27 (fixed in 62.0.27); from 64.0.0, before 64.0.33 (fixed in 64.0.33); from 66.0.1, before 66.0.2 (fixed in 66.0.2)
Published 2019-08-02. Last modified 2026-06-17.