CVE-2019-15107

critical

Description

An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability.

From the Tenable Blog

CVE-2019-15107: Exploit Modules Available for Remote Code Execution Vulnerability in Webmin
CVE-2019-15107: Exploit Modules Available for Remote Code Execution Vulnerability in Webmin

Published: 2019-08-19

The popular Linux/UNIX systems management tool has more than 3 million downloads per year and the vulnerability has been present for at least a year, putting many virtual UNIX management systems at risk.

References

https://github.com/shambhaviM18/cve-2019-15107-lab

https://github.com/viglia/cve-2019-15107

https://github.com/ArtemCyberLab/Project-Exploitation-of-Webmin-Authentication-Vulnerability

https://github.com/bayazid-bit/CVE-2019-15107

https://github.com/EdouardosStav/CVE-2019-15107-RCE-WebMin

https://github.com/m4lk3rnel/CVE-2019-15107

https://github.com/Mattb709/CVE-2019-15107-Scanner

https://github.com/MasterCode112/CVE-2019-15107

https://github.com/grayorwhite/CVE-2019-15107

https://github.com/NasrallahBaadi/CVE-2019-15107

https://github.com/wenruoya/CVE-2019-15107

https://github.com/Slimicide/Detect-CVEs

https://github.com/lolminerxmrig/CVE-2019-15107

https://github.com/NullBrunk/Webmin-RCE

https://github.com/NullBrunk/CVE-2019-15107

https://github.com/f0rkr/CVE-2019-15107

https://github.com/hadrian3689/webmin_1.920

https://github.com/hacknotes/CVE-2019-15107-Exploit

https://github.com/darrenmartyn/CVE-2019-15107

https://github.com/ChakoMoonFish/webmin_CVE-2019-15107

https://github.com/hannob/webminex

https://github.com/Pichuuuuu/verbose_happiness

https://github.com/Rayferrufino/Make-and-Break

https://github.com/g0db0x/CVE_2019_15107

https://github.com/AdministratorGithub/CVE-2019-15107

https://github.com/ketlerd/CVE-2019-15107

https://github.com/HACHp1/webmin_docker_and_exp

https://www.exploit-db.com/exploits/47230

https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-15107

http://www.webmin.com/security.html

http://www.pentest.com.tr/exploits/DEFCON-Webmin-1920-Unauthenticated-Remote-Command-Execution.html

http://packetstormsecurity.com/files/154197/Webmin-1.920-password_change.cgi-Backdoor.html

http://packetstormsecurity.com/files/154141/Webmin-Remote-Comman-Execution.html

http://packetstormsecurity.com/files/154141/Webmin-1.920-Remote-Command-Execution.html

Details

Source: Mitre, NVD

Published: 2019-08-16

Updated: 2026-08-06

Known Exploited Vulnerability (KEV)

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.99766