User has access to ALL accounts of server

ruber

Member
Jun 5, 2007
22
0
151
An user of my server, when it access cPanel, opens the "root" cPanel, with all features and the list to choose any account of the server. I had tested other accounts, but happens only with this customer. What can I do to solve this? It's a critical security hole on my cPanel, I changed the customer's password to avoid the access until I can fix this...
 

cPanelKenneth

cPanel Development
Staff member
Apr 7, 2006
4,607
79
458
cPanel Access Level
Root Administrator
An user of my server, when it access cPanel, opens the "root" cPanel, with all features and the list to choose any account of the server. I had tested other accounts, but happens only with this customer. What can I do to solve this? It's a critical security hole on my cPanel, I changed the customer's password to avoid the access until I can fix this...
If you changed the password and that disabled the behavior, then it sounds like his password was the same as the root password. If that is the case, then the following tweak setting is what is causing this:


Disable login with root or reseller password into the users' cPanel interface. Also disable switch account dropdown in themes with switch account feature.


Otherwise it may be as Infopro stated.
 

ruber

Member
Jun 5, 2007
22
0
151
If you changed the password and that disabled the behavior, then it sounds like his password was the same as the root password. If that is the case, then the following tweak setting is what is causing this:


Disable login with root or reseller password into the users' cPanel interface. Also disable switch account dropdown in themes with switch account feature.


Otherwise it may be as Infopro stated.

No, no...

I changed the password until this is solved, and the customer is not accessing his account until I change the password back and tell him. The accounts still appears, even with other password. I changed the password of another account to the same of that, and cPanel works fine, accessing only its account, not any other.

The problem occours only in ONE account, even changing password, recreating the account... How I can see this "Master Reseller" option? This account isn't a reseller.