Skip to main content

Privilege Escalation in UAPI function called by cPanel Interface

Comments

3 comments

  • cPanelMichael
    Note that I do have a WbAdminModule.conf file, created by running:

    Hello, Could you verify the permissions and ownership values configured on the WbAdminModule.conf file? Also, does it make a different if you adjust it's contents to resemble the following code? EX: mode=full allowed_parents=/usr/local/cpanel/cpanel
    Thank you.
    0
  • pwells
    Permissions of the conf file were 644 and owned by root:root -rw-r--r-- 1 root root 51 Feb 27 08:57 /usr/local/cpanel/bin/admin/WbAdminModule/WbAdminModule.conf
    I have tried updating the contents to: mode=full allowed_parents=/usr/local/cpanel/cpanel
    This has had no effect. I also tried updating permissions to 700, 770, 777, 600, 660 - none of these worked.
    0
  • cPanelMichael
    Hello, You are welcome to open a support ticket using the link in my signature so we can take a closer look and verify the functionality is working as intented. We can't troubleshoot the custom code itself, but we should be able to take a general look to see if there are any obvious mistakes in your implementation. Additionally, you can also send end an email to integration@cpanel.net to seek out additional feedback from our Developers. Thank you.
    0

Please sign in to leave a comment.