Remote Code Execution Vulnerability in Webmin by Vendor Webmin
CVE-2019-15642
Key Information:
Badges
What is CVE-2019-15642?
The vulnerability in the rpc.cgi module of Webmin version 1.920 allows authenticated users to execute arbitrary code remotely. This occurs through a crafted object name that exploits the unserialise_variable function, which inappropriately calls eval. Consequently, this can lead to unauthorized command execution or file modifications on the server. Proper access controls are crucial to mitigate risks as detailed in the Webmin_Servers_Index documentation.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
EPSS Score
91% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved