CVE-2019-15641: XEE
Published Aug 26, 2019
·Updated
xmlrpc.cgi in Webmin through 1.930 allows authenticated XXE attacks. By default, only root, admin, and sysadm can access xmlrpc.cgi.
Affected Software
1 affected component
webmin webmin<=1.930
Event History
Aug 26, 2019
CVE Published
via MITRE·05:07 PM
Data Sourced
via MITRE·05:07 PM
Description
Frequently Asked Questions
1
What is CVE-2019-15641?
CVE-2019-15641 is a vulnerability in Webmin that allows authenticated XXE attacks.
2
What is the severity of CVE-2019-15641?
CVE-2019-15641 has a severity rating of 6.5 (medium).
3
How does CVE-2019-15641 affect Webmin?
CVE-2019-15641 allows authenticated XXE attacks in Webmin versions up to 1.930.
4
Who can access xmlrpc.cgi by default in Webmin?
By default, only root, admin, and sysadm can access xmlrpc.cgi in Webmin.
5
Is there a fix for CVE-2019-15641?
To fix CVE-2019-15641, upgrade Webmin to a version above 1.930.