The "Allow cPanel users to reset their password via email" feature in cPanel 9.1.0 build 34 and earlier, including 8.x, allows remote attackers to execute arbitrary code via the user parameter to resetpass.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-08T01:00:37.211Z
Reserved: 2005-03-10T00:00:00
Link: CVE-2004-1769

No data.

Status : Deferred
Published: 2004-03-11T05:00:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2004-1769

No data.