Command Injection in Webmin - CVE-2019-15231,CVE-2019-15107
Published: August 27, 2019 / Updated: May 9, 2023
Vulnerability identifier: #VU20412
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-15231,CVE-2019-15107
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary commands on a targeted system.
The vulnerability exists due to insufficient validation of user-supplied input in the "password_change.cgi" script. A remote attacker can send a specially crafted HTTP request that submits malicious input to the password reset request form page and execute arbitrary commands with root privileges.
Note, this vulnerability is being exploited in the wild by the Roboto botnet.
Affected software
Webmin
How to mitigate CVE-2019-15231,CVE-2019-15107
Install updates from vendor's website.
Webmin - update to 1.930
Links to Public Exploits and PoC-codes
- Exploit #9059 - CVE-2019-15107-EXPLOIT (A PoC exploit for CVE-2019-15107 - Webmin Remote Code Execution) (May 9, 2023)
- Exploit #8778 - verbose_happiness (This is a script that exploits a known vulnerability (CVE-2019-15107) in web applications, allowing an attacker to inject commands on the target server. It takes a file containing a list of target URLs as input and attempts to find vuln (January 29, 2023)
- Exploit #8777 - CVE-2019-15107 (This is a script that exploits a known vulnerability (CVE-2019-15107) in web applications, allowing an attacker to inject commands on the target server. It takes a file containing a list of target URLs as input and attempts to find vulnera (January 29, 2023)
- Exploit #8643 - CVE-2019-15107 (Python3 code to exploit CVE-2019-15107 and CVE-2019-15231 ) (December 4, 2022)
- Exploit #8182 - MiniExploit (WebMin Versions <= 1.920 [CVE-2019-15107] RCE PoC) (July 26, 2022)
- Exploit #8096 - CVE-2019-15107 (Python3 code to exploit CVE-2019-15107 and CVE-2019-15231 ) (June 30, 2022)
- Exploit #8055 - CVE-2019-15107_webminRCE (unauthorized RcE exploit for webnin < 1.920) (June 19, 2022)
- Exploit #8018 - WebminExploit (Python3 code to CVE-2019-15107 and CVE-2019-15231) (June 12, 2022)
- Exploit #8016 - Webmin-RCE (Python3 code to exploit CVE-2019-15107 and CVE-2019-15231 ) (June 12, 2022)
- Exploit #6842 - CVE-2019-15107-Exploit (Exploit para CVE-2019-15107 (Webmin 1.890-1.920) sin credenciales RCE escrito en PYTHON.) (October 6, 2021)
- Exploit #5892 - Webmin 1.920 - Remote Code Execution (June 17, 2021)
- Exploit #4601 - Webmin_1.890-POC (CVE-2019-15107 exploit) (September 16, 2020)
- Exploit #4552 - CVE-2019-15107 (Webmin <=1.920 RCE) (September 1, 2020)
- Exploit #2184 - Make-and-Break (Built a custom Virtual Machine, running Ubuntu 18.04.1 and Webmin 1.810. Using CVE-2019-15107 to exploit a backdoor in the Linux machine) (March 18, 2020)
- Exploit #2183 - CVE_2019_15107 (CVE_2019_15107 Webmin 1.920 Remote Code Execution Exploit) (March 18, 2020)
- Exploit #2175 - CVE-2019-15107 (Implementation of CVE-2019-15107 exploit in python) (March 18, 2020)
- Exploit #2078 - webminex (poc exploit for webmin backdoor (CVE-2019-15107 and CVE-2019-15231)) (March 18, 2020)
- Exploit #1494 - Webmin password_change.cgi Backdoor (March 18, 2020)
- Exploit #1532 - Webmin password_change.cgi Backdoor (March 18, 2020)