CVE-2019-15107
A critical command injection flaw exists in Webmin versions up to 1.920. The vulnerability is triggered by the "old" parameter in password_change.cgi, allowing attackers to run arbitrary commands on the server. This can lead to full system compromise.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Webmin 1.920 and earlier, typically used by system administrators managing Linux/Unix servers.
Real-world impact
An attacker could execute any command on the affected server, potentially taking full control, exfiltrating data, or installing malware.
Why this severity
The CVSS score of 9.8 reflects that the flaw can be exploited remotely without authentication or user interaction, and it can compromise confidentiality, integrity, and availability of the system.
What to do about it
- 01Download the latest Webmin update from the official website.
- 02Install the update following the vendor's instructions.
- 03Restart the Webmin service.
CISA KEV required action
Timeline
- Aug 16, 2019 · Aug 16, 2019PublishedDisclosed and added to the National Vulnerability Database.
- Mar 25, 2022 · Mar 25, 2022Confirmed exploited (CISA KEV)CISA added it to the Known Exploited Vulnerabilities catalog — attackers are using it in the wild.
- Apr 15, 2022 · Apr 15, 2022CISA remediation deadlineFederal agencies are required to remediate by this date.
- Aug 4, 2026 · 2d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Aug 6, 2026 · 4h agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- packetstormsecurity.com/files/154141/Webmin-1.920-R…exploitthird party advisoryvdb entry
- packetstormsecurity.com/files/154141/Webmin-Remote-…exploitthird party advisoryvdb entry
- packetstormsecurity.com/files/154197/Webmin-1.920-p…exploitthird party advisoryvdb entry
- packetstormsecurity.com/files/154485/Webmin-1.920-R…third party advisoryvdb entry
- pentest.com.tr/exploits/DEFCON-Webmin-1920…exploitthird party advisory
- webmin.com/security.htmlvendor advisory
- attackerkb.com/topics/hxx3zmiCkR/webmin-pa…third party advisory
- exploit-db.com/exploits/47230exploitthird party advisoryvdb entry
- cisa.gov/known-exploited-vulnerabili…us government resource