Executive brief
Webmin versions 1.920 and prior contain a command injection vulnerability in the 'old' parameter of password_change.cgi. This allows unauthenticated remote attackers to execute arbitrary commands on the host system.
Affected products
- Webmin Webmin <= 1.920
Timeline
- 2019-08-27: disclosed: Initial analysis by NIST
- 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-03-25: advisory: NVD publication date