Security Advisory

CVE-2020-35606

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2020-12-21 19:19:17
Last updated 2024-08-04 17:09:14
Assigner mitre
State PUBLISHED

Description

Arbitrary command execution can occur in Webmin through 1.962. Any user authorized for the Package Updates module can execute arbitrary commands with root privileges via vectors involving %0A and %0C. NOTE: this issue exists because of an incomplete fix for CVE-2019-12840.