CVE-2015-2079: Code Injection
Published Apr 28, 2025
·Updated
Usermin 0.980 through 1.x before 1.660 allows uconfigsave.cgi sigfilefree remote code execution because it uses the two argument (not three argument) form of Perl open.
Affected Software
2 affected components
Usermin Usermin>=0.980<1.660
Webmin Usermin>=0.980<1.660
Event History
Apr 28, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2015-2079?
CVE-2015-2079 has a medium severity rating as it allows for remote code execution.
2
How do I fix CVE-2015-2079?
To fix CVE-2015-2079, you should upgrade Usermin to version 1.660 or later.
3
What versions of Usermin are affected by CVE-2015-2079?
Usermin versions from 0.980 up to, but not including, 1.660 are affected by CVE-2015-2079.
4
What type of vulnerability is CVE-2015-2079?
CVE-2015-2079 is a remote code execution vulnerability.
5
Who is impacted by CVE-2015-2079?
Users running vulnerable versions of Usermin prior to 1.660 are impacted by CVE-2015-2079.