Junglewise Threat Intelligence

CVE-2019-15107: Webmin Command Injection Vulnerability

CVE-2019-15107 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-25

Technologies: Webmin. Vendors: Webmin.

Executive brief

Webmin versions 1.920 and prior contain a command injection vulnerability in the 'old' parameter of password_change.cgi. This allows unauthenticated remote attackers to execute arbitrary commands on the host system.

Affected products

  • Webmin Webmin <= 1.920

Timeline

  • 2019-08-27: disclosed: Initial analysis by NIST
  • 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-25: advisory: NVD publication date

Related threats