yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2019-12840
Component Overview
Vulnerability Overview
Name
CVE-2019-12840
Source
NVD (
link
)
Debian (
link
)
Description
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root privileges via the data parameter to update.cgi.
CWEs
CWE-78
Published Date
Jun 15, 2019
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://pentest.com.tr/exploits/Webmin-1910-Package-Updates-Remote-Command-Execution.html
Exploit
https://www.exploit-db.com/exploits/46984
Exploit
https://pentest.com.tr/exploits/Webmin-1910-Package-Updates-Remote-Command-Execution.html
Exploit
https://www.exploit-db.com/exploits/46984
Exploit
Analysis
#
Affected Component
Analysis
webmin
Exploitable
Vulnerability Ratings
#
8.8
other
9
CVSSv2
Others affected components
#
Name
Project
Project Version
Version
Status
webmin
yocto
master
2.641
Not Affected
webmin
yocto
scarthgap
1.850
Exploitable