The WordPress.org privacy policy has been updated, hurray! While we weren’t able to remove all the long sentences, we hope you find the revisions make it easier to understand: how we collect and use data, how long the data we collect is retained, and how you can request a copy of the data you’ve shared […]
Archive for security
Communication Re-Opt In We’ve been preparing in several ways to support our commitments to customers and end users. Per GDPR regulations and our data processing practices, if you wish to receive communications from cPanel moving forward, you must re-opt in by completing this form. GDPR cPanel has recently updated a number of its agreements to facilitate GDPR compliance. We’ve done two things: We’ve revised our privacy policy …
This is a guest blog post provided by Kevin McGrail. Kevin is a respected member of the hosting industry, a huge supporter of the Open Source community, and an alumni speaker at the annual cPanel Conference. There are a lot of reasons to choose cPanel & WHM as your web hosting control panel. It’s got tons of features, great support and it lets everyone from Mom n’ Pop to Enterprise customers easily manage their hosting. …
- Project: Joomla!
- SubProject: CMS
- Impact: Low
- Severity: Low
- Versions: 1.5.0 through 3.8.7
- Exploit type: XSS
- Reported Date: 2017-October-28
- Fixed Date: 2018-May-22
- CVE Number: CVE-2018-6378
Description
Inadequate filtering of file and folder names lead to various XSS attack vectors in the media manager.
Affected Installs
Joomla! CMS versions 1.5.0 through 3.8.7
Solution
Upgrade to version 3.8.8
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: CMS
- Impact: Low
- Severity: Low
- Versions: 3.1.2 through 3.8.7
- Exploit type: XSS
- Reported Date: 2018-March-30
- Fixed Date: 2018-May-22
- CVE Number: CVE-2018-11328
Description
Under specific circumstances (a redirect issued with a URI containing a username and password when the Location: header cannot be used), a lack of escaping the user-info component of the URI could result in a XSS vulnerability.
Affected Installs
Joomla! CMS versions 3.1.2 through 3.8.7
Solution
Upgrade to version 3.8.8
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: CMS
- Impact: Medium
- Severity: Low
- Versions: 3.0.0 through 3.8.7
- Exploit type: Session race condition
- Reported Date: 2017-July-08
- Fixed Date: 2018-May-22
- CVE Number: CVE-2018-11324
Description
A long running background process, such as remote checks for core or extension updates, could create a race condition where a session which was expected to be destroyed would be recreated.
Affected Installs
Joomla! CMS versions 3.0.0 through 3.8.7
Solution
Upgrade to version 3.8.8
Additional Resources
- Links Go Here
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: CMS
- Impact: Moderate
- Severity: Low
- Versions: 3.7.0 through 3.8.7
- Exploit type: Remote Code Execution
- Reported Date: 2018-May-14
- Fixed Date: 2018-May-22
- CVE Number: CVE-2018-11321
Description
Inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an unvalidated option.
Affected Installs
Joomla! CMS versions 3.7.0 through 3.8.7
Solution
Upgrade to version 3.8.8
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: CMS
- Impact: Moderate
- Severity: Moderate
- Versions: 3.0.0 through 3.8.7
- Exploit type:XSS
- Reported Date:2018-February-02 & 2018-March-27
- Fixed Date: 2018-May-22
- CVE Number: CVE-2018-11326
Description
Inadequate input filtering leads to multiple XSS vulnerabilities. Additionally, the default filtering settings could potentially allow users of the default Administrator user group to perform a XSS attack.
Affected Installs
Joomla! CMS versions 3.0.0 through 3.8.7
Solution
Upgrade to version 3.8.8
Additional Resources
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: CMS
- Impact: Low
- Severity: Low
- Versions: 3.0.0 through 3.8.7
- Exploit type: Information Disclosure
- Reported Date: 2018-February-09
- Fixed Date: 2018-May-22
- CVE Number: CVE-2018-11325
Description
The web install application would autofill password fields after either a form validation error or navigating to a previous install step, and displays the plain text password for the administrator account at the confirmation screen.
Affected Installs
Joomla! CMS versions 3.0.0 through 3.8.7
Solution
Upgrade to version 3.8.8
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: CMS
- Impact: Low
- Severity: Moderate
- Versions: 3.1.0 through 3.8.7
- Exploit type: Information Disclosure
- Reported Date: 2018-April-27
- Fixed Date: 2018-May-22
- CVE Number: CVE-2018-11327
Description
Inadequate checks allowed users to see the names of tags that were either unpublished or published with restricted view permission .
Affected Installs
Joomla! CMS versions 3.1.0 through 3.8.7
Solution
Upgrade to version 3.8.8
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: CMS
- Impact: High
- Severity: Low
- Versions: 2.5.0 through 3.8.7
- Exploit type: Malicious file upload
- Reported Date: 2018-March-14
- Fixed Date: 2018-May-22
- CVE Number: CVE-2018-11322
Description
Depending on the server configuration, PHAR files might be handled as executable PHP scripts by the webserver.
Affected Installs
Joomla! CMS versions 2.5.0 through 3.8.7
Solution
Upgrade to version 3.8.8
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: CMS
- Impact: High
- Severity: Low
- Versions: 2.5.0 through 3.8.7
- Exploit type: ACL violation
- Reported Date: 2018-March-08
- Fixed Date: 2018-May-22
- CVE Number: CVE-2018-11323
Description
Inadequate checks allowed users to modify the access levels of user groups with higher permissions.
Affected Installs
Joomla! CMS versions 2.5.0 through 3.8.7
Solution
Upgrade to version 3.8.8
Contact
The JSST at the Joomla! Security Centre.
WordPress 4.9.6 is now available. This is a privacy and maintenance release. We encourage you to update your sites to take advantage of the new privacy features. Privacy The European Union’s General Data Protection Regulation (GDPR) takes effect on May 25. The GDPR requires companies and site owners to be transparent about how they collect, […]
Greetings and Salutations! Hello everyone! My name is Phil, and I am the newest member of the Community team at cPanel! I’m very excited to join the Community Team and work with everyone who touches cPanel & WHM! I have worked in the web hosting industry for about 7 years. My roles have included frontline support, system administrator, and communications. I’ve been very lucky in taking two things that I love (arguing and the internet) …
Git Version Control series: What is Git?
This is the first in a series of blog posts around Git and a new feature coming in version 72, Git Version Control. Watch for a new one every Wednesday! If you follow our feature request site, you already know about our upcoming feature, Git Version Control. We’re designing it to make hosting repositories as easy for developers as a “Hello World!” script. Before we send the feature your way, though, we want to …
As most any Hosting Provider will tell you, looking for new ways to promote services, gain more business, and earn new customers is one of the most important things they do every day. At the same time, both new and experienced cPanel users alike are visiting these Hosting Providers sites looking at what they’re offering. There are, of course, an unlimited number of reasons people shop around for new hosting, and those reasons are always evolving. …
Introducing mod_cpanel
As of the second cPanel & WHM Targeted Security Release of 2018 (TSR-2018-0002), the Optimize .htaccess feature was removed from all supported cPanel & WHM versions. This difficult decision was the result of some security concerns with its implementation. In its place, we have released the mod_cpanel Apache module. This module will begin to improve upon the features that Optimize .htaccess provided. What is Optimize .htaccess and why is cPanel replacing it? When we released it, …
Are you coming to cPConf 2018?
The Annual cPanel Conference is a staple in the webhosting community. Last year’s conference was such a blast! We met so many new people and got to catch up with all our old friends. The details of this year’s cPanel Conference (October 1-3, in Houston, Texas) are falling into place, and we’re looking forward to having you join us! Who will be there? Companies and disciplines from every corner of the hosting industry will be represented.
Zero to WordPress
Here at cPanel, Inc., we want to empower our users to take control of their own cPanel & WHM server. This can seem very daunting at first, but we are here to show you anyone can build a cPanel & WHM server with a WordPress site. We will be addressing some very technical topics, but have linked additional tutorials with more information. Let’s begin! Getting Started By the end of this tutorial, you will have purchased …
Update on GDPR Progress
It’s been just about two months since our last update. Our GDPR compliance efforts are moving quickly. We are in the final stages of preparing a privacy policy that meets the requirements of the U.S. / EU / Swiss Privacy Shield process. If are a customer, and you need an advance copy of our privacy policy to facilitate your GDPR efforts, please email gdprquestions [at] cpanel.net. Data processing agreements We will soon be updating our …
Greetings! Hello everyone! My name is Megan and I’m the newest Community Manager to join the team at cPanel. I’m really excited to join the team and ready to hit the ground running. I have a background in community outreach and digital marketing. Over the last year and a half, I became involved in the startup and tech community by participating in hackathons, organizing events, and learning to code. I am also one of the curators for Houston Startup Digest. My hobbies …
The post New Plesk Extensions on the Loose: May Edition appeared first on Plesk.
This past month saw a lot of preparation for upcoming events and releases across the WordPress project. Read on to find out more about these plans, and everything else that happened around the community in April. The WordPress 15th Anniversary is Coming On May 27 2018, WordPress will turn 15 years old — this is […]
It’s been almost two months since we announced the delay of cPanel & WHM Version 70. In that time, we’ve done a whole lot of work. We’re entering brand new territory for us, and Version 70 is at the center of it all. Why the Delay? In late January of this year, we found a performance issue in our backup system that we needed to address before v70 went to the RELEASE tier. Our research revealed …
Greg Zemslov, Guest Author from our Plesk partner Revisium talks about the websites threats that we don’t see, like site malware, and how to get rid of it.
The post Hidden Website Threats: How to deal with Site Malware appeared first on Plesk.
May 27, 2018 is the 15th anniversary of the first WordPress release — and we can’t wait to celebrate! Party time! Join WordPress fans all over the world in celebrating the 15th Anniversary of WordPress by throwing your own party! Here’s how you can join in the fun: Check the WordPress 15th Anniversary website to see […]
The Death of SquirrelMail
As of cPanel & WHM version 74, we will begin to deprecate our support of SquirrelMail, one of our bundled webmail applications. We expect to stop shipping SquirrelMail for new installations of cPanel & WHM in version 76 and will remove our support with version 78. As this change will disrupt many users, we are taking this opportunity to explain the reasons behind our decision. We also are opening a dialogue with you, our community, about …
GDPR compliance is an important consideration for all WordPress websites. The GDPR Compliance team is looking for help to test the privacy tools that are currently being developed in core.
We’ve added greater flexibility to how cPanel users can manage, protect, and administer email addresses on their mail server. You can now suspend or queue the outgoing mail from a single email account on your server. In case you’re not already familiar with the full administrative capabilities of Webmail, here’s a short run down. Receive Notifications of Send Limits Get alerts about accounts that are sending massive amounts of emails by entering Tweak Settings …
Last night, we pushed an update to EasyApache4 wherein after the update was installed Apache service may fail to restart properly. Upon checking the Apache error log, you may see error messaging similar to the following: Server xxxxxxx.com Primary IP Address xxxxxxxxxx Service Name httpd Service Status failed Notification The service “httpd” appears to be down. Service Check Method The system failed to connect to this service’s TCP/IP port. Reason Service check failed to complete …