CVE-2019-12840

HIGH

Webmin < 1.910 - OS Command Injection

Title source: rule

Description

In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root privileges via the data parameter to update.cgi.

Exploits (9)

nomisec WORKING POC 8 stars
by KrE80r · poc
https://github.com/KrE80r/webmin_cve-2019-12840_poc
nomisec WORKING POC 4 stars
by bkaraceylan · poc
https://github.com/bkaraceylan/CVE-2019-12840_POC
nomisec WORKING POC
by zAbuQasem · poc
https://github.com/zAbuQasem/CVE-2019-12840
nomisec WORKING POC
by WizzzStark · poc
https://github.com/WizzzStark/CVE-2019-12840.py
nomisec SUSPICIOUS
by anasbousselham · poc
https://github.com/anasbousselham/webminscan
nomisec WORKING POC
by fenix0499 · poc
https://github.com/fenix0499/CVE-2019-12840-NodeJs-Exploit
nomisec WORKING POC
by Pol-Ruiz · poc
https://github.com/Pol-Ruiz/PoC-CVE-2019-12840
exploitdb WORKING POC VERIFIED
by AkkuS · rubyremotelinux
https://www.exploit-db.com/exploits/46984
metasploit WORKING POC EXCELLENT
by AkkuS <Özkan Mustafa Akkuş> · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/webmin_packageup_rce.rb

Scores

CVSS v3 8.8
EPSS 0.8966
EPSS Percentile 99.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-78
Status published

Affected Products (1)

webmin/webmin < 1.910

Timeline

Published Jun 15, 2019
Tracked Since Feb 18, 2026