First published: Sat Jun 15 2019(Updated: )
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root privileges via the data parameter to update.cgi.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webmin Webmin | <=1.910 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-12840 is a vulnerability found in Webmin through version 1.910 that allows any user authorized to the 'Package Updates' module to execute arbitrary commands with root privileges.
CVE-2019-12840 has a severity rating of 8.8, which is classified as critical.
The affected software is Webmin through version 1.910.
The vulnerability can be exploited by any user authorized to the 'Package Updates' module using the data parameter in update.cgi.
Yes, you can find more information about CVE-2019-12840 at the following references: [http://packetstormsecurity.com/files/153372/Webmin-1.910-Remote-Command-Execution.html](http://packetstormsecurity.com/files/153372/Webmin-1.910-Remote-Command-Execution.html), [http://www.securityfocus.com/bid/108790](http://www.securityfocus.com/bid/108790), [https://pentest.com.tr/exploits/Webmin-1910-Package-Updates-Remote-Command-Execution.html](https://pentest.com.tr/exploits/Webmin-1910-Package-Updates-Remote-Command-Execution.html).