Dangerous file upload in Webmin - CVE-2019-9624

 

Dangerous file upload in Webmin - CVE-2019-9624

Published: March 8, 2019


Vulnerability identifier: #VU17929
CSH Severity: Medium
CVSS v4: 6.4 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H]
CVE-ID: CVE-2019-9624
CWE-ID: CWE-434
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to the application allows uploading of .cgi files via the /updown/upload.cgi URL. A remote authenticated attacker with Java file manager and Upload and Download privileges can upload and execute arbitrary .cgi file on the server with root privileges.


Affected software

Webmin

How to mitigate CVE-2019-9624

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.


Links to Public Exploits and PoC-codes

External References

Related Security Bulletins