peter bassill · operator
$ cve CVE-2020-35606 JSON

CVE-2020-35606 EXPLOIT

8.8
HIGH · CVSS 3.1 · EPSS 28% (pctl 98)

Patch early

A public exploit exists.

Description

Arbitrary command execution can occur in Webmin through 1.962. Any user authorized for the Package Updates module can execute arbitrary commands with root privileges via vectors involving %0A and %0C. NOTE: this issue exists because of an incomplete fix for CVE-2019-12840.

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS28.05% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploityes
Published2020-12-21
Last modified2026-06-17

Affected (1)

VendorProduct
webminwebmin

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD