CVE-2012-4893 PUBLISHED CVSS 6.800000190734863 MEDIUM

Multiple cross-site request forgery (CSRF) vulnerabilities in file/show.cgi in Webmin 1.590 and earlier allow remote attackers to hijack the authentication of privileged users for requests that (1) read files or execute (2) tar, (3) zip, or (4) gzip commands, a different issue than CVE-2012-2982.

EPSS 0.60% · 69.4th percentile

Risk Scores

CVSS v2.0
6.800000190734863
EPSS Score
0.60%
69.4th percentile

Affected Products

VendorProductVersions
n/an/an/a
gentoowebmin0, 1.140, 1.150

Timeline

References

Open in Interactive Console →