VulnerabilityModified
CVE-2020-35606
Arbitrary command execution can occur in Webmin through 1.962.
HIGH 8.8EPSS 28.0%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 28.0%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Arbitrary command execution can occur in Webmin through 1.962. Any user authorized for the Package Updates module can execute arbitrary commands with root privileges via vectors involving %0A and %0C. NOTE: this issue exists because of an incomplete fix for CVE-2019-12840.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 28.05% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- webmin/webmin
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/160676/Webmin-1.962-Remote-Command-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/49318Exploit, Third Party Advisory, VDB Entry
- https://www.pentest.com.tr/exploits/Webmin-1962-PU-Escape-Bypass-Remote-Command-Execution.htmlExploit, Third Party Advisory
- https://www.webmin.com/download.htmlProduct
- http://packetstormsecurity.com/files/160676/Webmin-1.962-Remote-Command-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/49318Exploit, Third Party Advisory, VDB Entry
- https://www.pentest.com.tr/exploits/Webmin-1962-PU-Escape-Bypass-Remote-Command-Execution.htmlExploit, Third Party Advisory
- https://www.webmin.com/download.htmlProduct
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.