Security bug in cPanel login

jdr

Registered
May 22, 2012
1
0
51
cPanel Access Level
Reseller Owner
Hi,

turns out this is probably the easiest way to report a problem...

You have (what I'd consider) a security bug in your cPanel login system. On a reseller account (for example) if a user has the same password as the administrator then even if the user logs into their site with their username and their password (which happens to be the same as the admin) then they get logged in as the admin! = Not good!!

James
 

Infopro

Well-Known Member
May 20, 2003
17,113
511
613
Pennsylvania
cPanel Access Level
Root Administrator
Twitter
Hi,

turns out this is probably the easiest way to report a problem...
Hi, not really. This is the proper way: http://go.cpanel.net/bugs


I believe this thread from back in 2008 should shed some light on your post though:
User password the same as root issue - cPanel Forums

Or more precisely this Documentation:
Accounts that can access a cPanel user account - cPanel Documentation

You'll find the setting to change this located here:
WHM > Server Configuration > Tweak Settings, System Tab, first item at top:
Accounts that can access a cPanel user account: cPanel User Only (might be best at all times unless otherwise needed)

Hope that helps!