CVE-2012-4893: CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in file/show.cgi in Webmin 1.590 and earlier allow remote attackers to hijack the authentication of privileged users for requests that (1) read files or execute (2) tar, (3) zip, or (4) gzip commands, a different issue than CVE-2012-2982.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4893?
The severity of CVE-2012-4893 is high due to its potential to allow remote attackers to hijack the authentication of privileged users.
How do I fix CVE-2012-4893?
To fix CVE-2012-4893, upgrade Webmin to version 1.591 or later, which addresses the CSRF vulnerabilities.
What are the risks associated with CVE-2012-4893?
CVE-2012-4893 poses risks such as unauthorized actions like reading sensitive files and executing commands as a privileged user.
Which versions of Webmin are affected by CVE-2012-4893?
CVE-2012-4893 affects Webmin versions 1.590 and earlier.
What type of vulnerability is CVE-2012-4893?
CVE-2012-4893 is classified as a cross-site request forgery (CSRF) vulnerability.