WHMCS
cpe:2.3:a:whmcs:whmcompletesolution:*:*:*:*:*:*:*, +1 more
- >= 9, < 9.0.4
- >= 8, < 8.13.3
- > 7.4.0
A vulnerability exists in WHMCS versions 7.4 and later, specifically within the Client Area. The issue arises from inadequate ownership checks in 'clientarea.php', which permit an authenticated user to submit requests using another user's 'addonId'. This lack of validation can lead to unauthorized access to the victim's resources and cPanel account.
Exploitation of this vulnerability could allow an authenticated WHMCS user to access and manipulate another user's account resources, including cPanel services, without authorization.
Users must upgrade to WHMCS versions 9.0.4 or 8.13.3. WHMCS Cloud users do not need to take any action, as all Cloud-hosted installations have already been updated.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.