Impact
Renaming databases in cPanel fails to preserve the SQL mode, permitting a user with rename permissions to execute arbitrary SQL statements as the database root user. This flaw is a classic SQL injection (CWE‑89) that escalates database privileges and can compromise data integrity and confidentiality.
Affected Systems
The vulnerability impacts cPanel installations managed by WebPros, notably the cPanel product itself. Affected versions are not explicitly listed, but the issue exists in releases prior to the fix referenced in the cPanel changelog and support article.
Risk and Exploitability
With a CVSS score of 9.4 the flaw is considered critical, yet the EPSS score is below 1%, suggesting exploitation is unlikely under current threat intelligence. The vulnerability is not cataloged in the CISA KEV list but remains a high‑impact risk for any environment where database renaming privileges are granted.
OpenCVE Enrichment