Security Alert : cPanel 11.25 CSRF vulnerability to upload any php Script !

0
57

Security Alert : cPanel 11.25 CSRF vulnerability to upload any php Script !

cPanel versions below and excluding 11.25 , are vulnerable to CSRF which leads to uploading a PHP script of the attackers liking. If you have turned off security tokens and referrer security check, no matter what version you are using, you are vulnerable as well.

Proof Of Concept :

<html>

<form name= »editform » 

Source: Security Alert : cPanel 11.25 CSRF vulnerability to upload any php Script !