Hello cloudlinux team,
i noticed cPanel "File Manager" working not in cage and support symlinks following, it allows normal cpanel user upload own symlink pointed to some file (for example /etc/passwd) or directory at server with global readable permissions and read it, also user can just put some files in writeable directory to run out all inodes at partition. Also i noticed cpanel user can just write into own "etc/website_folder/passwd and shadow" for create new mailboxes avoiding plan limits. Please explain it bugs or just missconfiguration?
i noticed cPanel "File Manager" working not in cage and support symlinks following, it allows normal cpanel user upload own symlink pointed to some file (for example /etc/passwd) or directory at server with global readable permissions and read it, also user can just put some files in writeable directory to run out all inodes at partition. Also i noticed cpanel user can just write into own "etc/website_folder/passwd and shadow" for create new mailboxes avoiding plan limits. Please explain it bugs or just missconfiguration?
Comment