PT-2019-2989 · Webmin · Webmin

·

CVE-2019-15107

·

Published

2019-08-16

·

Updated

2026-08-06

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Webmin versions 1.882 through 1.921
Description An issue exists in the password change.cgi endpoint of the administration web interface. The old parameter is susceptible to command injection due to improper neutralization of special elements used in a command. This allows a remote attacker to execute arbitrary shell commands on the target system with root privileges without authentication by sending a malicious POST request. This issue was found in official builds distributed via Sourceforge.
Recommendations Update Webmin to version 1.930 or later. As a temporary mitigation, disable the option to change expired passwords. Restrict access to the password change.cgi endpoint to minimize the risk of exploitation.

Exploit

Fix

DoS

OS Command Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-02968
CVE-2019-15107
MGASA-2019-0237

Affected Products

Webmin