RULE(RULE ID:323757)

Rule General Information
Release Date: 2019-11-28
Rule Name: Webmin Package Updates Remote Command Execution Vulnerability (CVE-2019-12840)
Severity:
CVE ID:
Rule Protection Details
Description: In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root privileges via the data parameter to update.cgi.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Others
Reference: SecurityFocusBID:108790
ExploitDB:46984
http://packetstormsecurity.com/files/153372/Webmin-1.910-Remote-Command-Execution.html
https://pentest.com.tr/exploits/Webmin-1910-Package-Updates-Remote-Command-Execution.html
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://www.webmin.com/