ZeroHour

CVE-2019-12840

PoC ×2
CVSS 3.0
8.8 high
EPSS
78%p100
Published
()
Modified
Description

In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root privileges via the data parameter to update.cgi.

Vendors
webmin
Products
webmin
Weakness
CWE-78
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.