CVE-2019-15107: Webmin Command Injection Vulnerability
An issue was discovered in Webmin <=1.920. The parameter old in passwordchange.cgi contains a command injection vulnerability.
Other sources
An issue was discovered in Webmin. The parameter old in passwordchange.cgi contains a command injection vulnerability.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable or remove the password_change.cgi handler (which processes the 'old' parameter) to prevent exploitation of the command injection until an official fix is available.
Webmin (password_change.cgi) password_change.cgi access = disabled - Compensating control
Restrict access to the Webmin management interface to trusted IPs (firewall/ACL) and/or place Webmin behind a VPN or jump-host until a patch or fixed version addressing the vulnerability in password_change.cgi is available.
Event History
Frequently Asked Questions
What is CVE-2019-15107?
CVE-2019-15107 is a vulnerability in Webmin <=1.920 that allows for command injection.
What is the severity of CVE-2019-15107?
CVE-2019-15107 has a severity rating of 9.8 (Critical).
How does CVE-2019-15107 affect Webmin?
CVE-2019-15107 affects Webmin versions up to 1.920.
What is the CWE classification for CVE-2019-15107?
CVE-2019-15107 has the CWE classification of CWE-77 and CWE-78.
Are there any references related to CVE-2019-15107?
Yes, you can find more information about CVE-2019-15107 at the following references: [link1], [link2], [link3].