VulnerabilityModified
CVE-2019-9624
Webmin 1.900 allows remote attackers to execute arbitrary code by leveraging the "Java file manager" and "Upload and Download" privileges to upload a crafted .cgi file via the /updown/upload.cgi URI.
HIGH 7.8EPSS 23.7%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 23.7%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Webmin 1.900 allows remote attackers to execute arbitrary code by leveraging the "Java file manager" and "Upload and Download" privileges to upload a crafted .cgi file via the /updown/upload.cgi URI.
- CVSS 3.0
- 7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 23.69% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-269
- Affected
- webmin/webmin
- Source
- cve@mitre.org
References
- http://www.rapid7.com/db/modules/exploit/unix/webapp/webmin_upload_execThird Party Advisory
- https://pentest.com.tr/exploits/Webmin-1900-Remote-Command-Execution.htmlExploit, Third Party Advisory
- https://www.exploit-db.com/exploits/46201Exploit, Third Party Advisory, VDB Entry
- http://www.rapid7.com/db/modules/exploit/unix/webapp/webmin_upload_execThird Party Advisory
- https://pentest.com.tr/exploits/Webmin-1900-Remote-Command-Execution.htmlExploit, Third Party Advisory
- https://www.exploit-db.com/exploits/46201Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.