Logo
vulnerabilityCVE-2019-12840
Name
CVE-2019-12840
Source
NVD ( link)Debian ( link)
Description
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root privileges via the data parameter to update.cgi.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
webmin
Exploitable

Vulnerability Ratings#


8.8
other
9
CVSSv2

Others affected components#


Name
Project
Project Version
Version
Status
yocto
master
2.641
Not Affected
yocto
scarthgap
1.850
Exploitable