CVE-2020-35606
21.12.2020, 20:15
Arbitrary command execution can occur in Webmin through 1.962. Any user authorized for the Package Updates module can execute arbitrary commands with root privileges via vectors involving %0A and %0C. NOTE: this issue exists because of an incomplete fix for CVE-2019-12840.
Vendor | Product | Version |
---|---|---|
webmin | webmin | 𝑥 ≤ 1.962 |
𝑥
= Vulnerable software versions
References