EXPOSURES › CVE-2019-15107
CVE-2019-15107
CRITICAL ⌖ ON CISA KEV · EXPLOITEDWebmin's password change functionality contained a command injection vulnerability actively exploited by ransomware actors, allowing attackers to execute arbitrary commands on vulnerable systems.
CVE-2019-15107 in Webmin allowed attackers to inject commands via the `old` parameter in `password_change.cgi`, leading to remote code execution and potential ransomware deployment. DIB organizations using Webmin must immediately patch or mitigate this vulnerability to prevent unauthorized access and data compromise, impacting CMMC/NIST 800-171 compliance controls related to access control and incident response.
Shame score — The vulnerability's exploitation by ransomware demonstrates a severe lack of secure coding practices and a failure to protect sensitive system configurations.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An issue was discovered in Webmin. The parameter old in password_change.cgi contains a command injection vulnerability.