CVE-2020-35606
EUVD-2020-2327221.12.2020, 20:15
Arbitrary command execution can occur in Webmin through 1.962. Any user authorized for the Package Updates module can execute arbitrary commands with root privileges via vectors involving %0A and %0C. NOTE: this issue exists because of an incomplete fix for CVE-2019-12840.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| webmin | webmin | 𝑥 ≤ 1.962 |
𝑥
= Vulnerable software versions
References