Skip to content
COOEY

EXPOSURES › CVE-2019-15107

CVE-2019-15107

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-15107 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwarerceexploited-in-wildunpatched

Webmin's password change functionality contained a command injection vulnerability actively exploited by ransomware actors, allowing attackers to execute arbitrary commands on vulnerable systems.

CVE-2019-15107 in Webmin allowed attackers to inject commands via the `old` parameter in `password_change.cgi`, leading to remote code execution and potential ransomware deployment. DIB organizations using Webmin must immediately patch or mitigate this vulnerability to prevent unauthorized access and data compromise, impacting CMMC/NIST 800-171 compliance controls related to access control and incident response.

Shame score — The vulnerability's exploitation by ransomware demonstrates a severe lack of secure coding practices and a failure to protect sensitive system configurations.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

An issue was discovered in Webmin. The parameter old in password_change.cgi contains a command injection vulnerability.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.