CVE-2019-15107 is a critical command injection vulnerability affecting Webmin versions up to 1.920, specifically within the 'old' parameter of the password_change.cgi script. This vulnerability carries a CVSS score of 9.8, indicating a severe unauthenticated remote attack that can lead to complete compromise (confidentiality, integrity, and availability). It is actively exploited in the wild, with readily available exploit code in Metasploit and Nuclei templates, and has garnered significant community and media attention, including its use by Mirai and Roboto botnets.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.920CPE matchmatch criteria | cpe:2.3:a:webmin:webmin:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.