CVE-2019-12840
HIGH 9.0EPSS 77.8%
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root privileges via the data parameter to update.cgi.
- CVSS v3.0
- 8.8 HIGH
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 9.0 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C - EPSS
- 77.83% chance of exploitation in the next 30 days, 100th percentile
- Published
- 2019-06-15
- Updated
- 2024-08-04
Proof-of-concept exploits (8)
- https://pentest.com.tr/exploits/Webmin-1910-Package-Updates-Remote-Command-Execution.html
- KrE80r/webmin_cve-2019-12840_poc8★ · 2019-11-10
- Pol-Ruiz/PoC-CVE-2019-128400★ · 2024-01-25
- WizzzStark/CVE-2019-12840.py0★ · 2021-10-05
- bkaraceylan/CVE-2019-12840_POC4★ · 2019-11-05
- fenix0499/CVE-2019-12840-NodeJs-Exploit0★ · 2025-06-04
- zAbuQasem/CVE-2019-128400★ · 2021-09-19
- note0577/CVE-2019-12840-NodeJs-Exploit