vulnerability
CVE-2019-15107: Webmin: Unauthenticated Remote Code Execution
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 9 | (AV:N/AC:L/Au:N/C:C/I:C/A:C) | Aug 15, 2019 | Feb 4, 2020 | May 3, 2022 |
Severity
9
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
Aug 15, 2019
Added
Feb 4, 2020
Modified
May 3, 2022
Description
The SourceForge downloads of Webmin versions 1.890 through 1.920, listed as official downloads on the project's site,
were backdoored, such that it contains a remote code execution vulnerability in the 'old' and 'expired' parameters of password_change.cgi.
Solution
webmin-upgrade-latest
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.