cPanel 11.19.0-EDGE_20931 - resellers can overwrite the crt, key, and csr of the server's hostname



DESCRIPTION


Resellers were able to overwrite the crt, key, and csr of the server's hostname via "Generate a SSL Certificate and Signing Request".



IMPACT


Given sufficient access, man in the middle attacks could be possible.