#VU18817 OS Command Injection in Webmin - CVE-2019-12840
Published: June 18, 2019 / Updated: June 17, 2021
Webmin
Webmin
Description
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to insufficient sanitization of user-supplied data passed via the "u" HTTP POST parameter to "update.cgi" script. A remote authenticated attacker can send a specially crafted request to the Package Updates module and execute arbitrary OS commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system bit requires access to Package Updates module.