CVE-2017-6513: Softaculous Whmcs Reseller Module

Critical severity, CVSS 9.9. EPSS: 1.3% chance of exploitation in the next 30 days.

The WHMCS Reseller Module V2 2.0.2 in Softaculous Virtualizor before 2.9.1.0 does not verify the user correctly, which allows remote authenticated users to control other virtual machines managed by Virtualizor by accessing a modified URL.

Affected products

Published 2017-03-11. Last modified 2026-06-17.