Digital Defense, Inc. Discloses cPanel® & WHM® Vulnerability
Summary
cPanel &WHM version 11.90.0.5 (90.0 Build 5) exhibits a two-factor authentication bypass flaw, vulnerable to brute force attack, resulting in a scenario where an attacker with knowledge of or access to valid credentials could bypass two-factor authentication protections on an account. “Our standard practice is to work in tandem with organizations on a coordinated disclosure effort to facilitate a prompt resolution to a vulnerability. We will continue outreach to customers ensuring they are aware and able to take action to mitigate any potential risk introduced by the vulnerability,” states Mike Cotton, senior vice president of engineering at Digital Defense. The expertise of the VRT, when coupled with the company’s next generation hybrid cloud platform, Frontline Vulnerability Manager, enables early detection capabilities. The Digital Defense Frontline suite of solutions, underpinned by patented technology and complemented with superior service and support, are highly-regarded by industry experts, as illustrated by the company’s designation as a 2020 Hot 150 Cybersecurity Company, 2020 Tag Cyber Distinguished Vendor, 2020 U.S. Department of Labor Platinum Medallion Award, a five-star review in SC Magazine and CRN 5-Star Partner Program rating.