Vulnerability Database

300,445

Total vulnerabilities in the database

CVE-2019-12840

In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root privileges via the data parameter to update.cgi.

  • Published: Jun 15, 2019
  • Updated: Nov 9, 2025
  • CVE: CVE-2019-12840
  • Severity: High
  • Exploit:

CVSS v2:

  • Severity: High
  • Score: 9
  • AV:N/AC:L/Au:S/C:C/I:C/A:C

CWEs:

OWASP TOP 10: