vendor:
Webmin
by:
AkkuS
8.8
CVSS
HIGH
Remote Command Execution
78
CWE
Product Name: Webmin
Affected Version From: 1.910
Affected Version To: 1.910
Patch Exists: YES
Related CWE: CVE-2019-12840
CPE: a:webmin:webmin
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Unix
2019
Webmin Package Updates Remote Command Execution
This module exploits an arbitrary command execution vulnerability in Webmin 1.910 and lower versions. Any user authorized to the 'Package Updates' module can execute arbitrary commands with root privileges.
Mitigation:
Upgrade to Webmin version 1.920 or later