Impact
The flaw is an HTTP request smuggling vulnerability found in cPanel that can lead to the leakage of authentication credentials. By manipulating the formatting of HTTP requests, an attacker could coerce the server into interpreting the request incorrectly, thereby exposing sensitive credential information. This weakness is classified as CWE‑444 – an unsafe removal of protocol headers or components, which directly threatens data confidentiality.
Affected Systems
This vulnerability affects cPanel and the WP Squared platform developed by WebPros. No specific product versions are listed in the advisory, so administrators should verify whether their current deployments are impacted against the vendor’s published guidance.
Risk and Exploitability
The CVSS score of 5.6 marks it as a medium‑severity flaw, while the EPSS score of less than 1% indicates a very low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is network‑based request manipulation; an attacker could construct malformed HTTP traffic that is processed incorrectly by the target server, potentially capturing credential data in the process.
OpenCVE Enrichment