Impact
The vulnerability stems from improper privilege handling and insufficient path filtering in the cpdavd attachment download endpoints, enabling an attacker to read any file on the server. This flaw can expose configuration files, credentials, and other sensitive data, compromising confidentiality and potentially enabling further exploitation.
Affected Systems
The flaw affects WebPros’ WP Squared and cPanel products. No specific version numbers are listed in the advisory, so any installation of these products may be impacted until the issue is patched.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity, while the EPSS score of <1% denotes a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed wild exploits yet. The likely attack vector is a web‑based request to a cpdavd endpoint, potentially requiring user authentication but not guaranteed to be unauthenticated, allowing an attacker to read arbitrary files if the endpoints are reachable.
OpenCVE Enrichment