CVE-2017-18425: cPanel

Low severity, CVSS 2.5. EPSS: 0.3% chance of exploitation in the next 30 days.

In cPanel before 66.0.2, the cpdavd_error_log file can be created with weak permissions (SEC-280).

Affected products

  • cPanel cPanel: from 56.0.1, before 56.0.51 (fixed in 56.0.51); from 58.0.3, before 58.0.52 (fixed in 58.0.52); from 60.0.3, before 60.0.45 (fixed in 60.0.45); from 62.0.1, before 62.0.27 (fixed in 62.0.27); from 64.0.0, before 64.0.33 (fixed in 64.0.33); from 66.0.1, before 66.0.2 (fixed in 66.0.2)

Published 2019-08-02. Last modified 2026-06-17.