← Back to browse · API

CVE-2024-12828

Severity
CRITICAL
CVSS
9.9
EPSS
0.33467
Risk score
51.31
CISA KEV
No
PoC
No
Published
2024-12-30
Modified
2024-12-30
First seen
2026-08-07
Aliases
EUVD-2024-51130, GHSA-R6M7-83VQ-QX32
Products
Webmin:Webmin webmin 2.104
Sources
euvd EUVD-2024-51130

Description

Webmin CGI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Webmin. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of CGI requests. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-22346.

References