CVE-2019-12840
60Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 78%
from disclosure to weapon143 days
Published on NVDJun 15
1st PoC+143d
metasploitMay 16
exploitation probability
78%top 1% of all CVEs
observed exploitation
nono source reports it
9 public exploit(s)
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root privileges via the data parameter to update.cgi.
Affected products
n/a · n/apublic PoCs found — 9✓ VexDay Proof
cve_reference✓ VexDay Proofwww.exploit-db.com/exploits/46984githubgithub.com/KrE80r/webmin_cve-2019-12840_poc★ 8githubgithub.com/bkaraceylan/CVE-2019-12840_POC★ 4githubgithub.com/WizzzStark/CVE-2019-12840.py★ 0githubgithub.com/Pol-Ruiz/PoC-CVE-2019-12840★ 0githubgithub.com/fenix0499/CVE-2019-12840-NodeJs-Exploit★ 0githubgithub.com/anasbousselham/webminscan★ 0githubgithub.com/zAbuQasem/CVE-2019-12840★ 0cve_referencepacketstormsecurity.com/files/153372/Webmin-1.910-Remote-Command-Execution.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.