git: a3a5f02d91fb - main - security/vuxml: Document CVE-2024-12828 (CGI Command Injection RCE in webmin)
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Sun, 15 Jun 2025 11:30:29 UTC
The branch main has been updated by olgeni:
URL: https://cgit.FreeBSD.org/ports/commit/?id=a3a5f02d91fb709e88eeed99a393c4be500b3e93
commit a3a5f02d91fb709e88eeed99a393c4be500b3e93
Author: Jimmy Olgeni <olgeni@FreeBSD.org>
AuthorDate: 2025-06-15 11:23:10 +0000
Commit: Jimmy Olgeni <olgeni@FreeBSD.org>
CommitDate: 2025-06-15 11:26:55 +0000
security/vuxml: Document CVE-2024-12828 (CGI Command Injection RCE in webmin)
---
security/vuxml/vuln/2025.xml | 27 +++++++++++++++++++++++++++
1 file changed, 27 insertions(+)
diff --git a/security/vuxml/vuln/2025.xml b/security/vuxml/vuln/2025.xml
index fc969d9836b6..8798a5c29639 100644
--- a/security/vuxml/vuln/2025.xml
+++ b/security/vuxml/vuln/2025.xml
@@ -1,3 +1,30 @@
+ <vuln vid="805ad2e0-49da-11f0-87e8-bcaec55be5e5">
+ <topic>webmin -- CGI Command Injection Remote Code Execution</topic>
+ <affects>
+ <package>
+ <name>webmin</name>
+ <range><le>2.105</le></range>
+ </package>
+ </affects>
+ <description>
+ <body xmlns="http://www.w3.org/1999/xhtml">
+ <p>Webmin reports:</p>
+ <blockquote cite="https://webmin.com/security/">
+ <p>A less-privileged Webmin user can execute commands as root via a vulnerability in the shell autocomplete feature.</p>
+ </blockquote>
+ </body>
+ </description>
+ <references>
+ <cvename>CVE-2024-12828</cvename>
+ <url>https://webmin.com/security/</url>
+ <url>https://nvd.nist.gov/vuln/detail/CVE-2024-12828</url>
+ </references>
+ <dates>
+ <discovery>2024-12-30</discovery>
+ <entry>2025-06-15</entry>
+ </dates>
+ </vuln>
+
<vuln vid="ae028662-475e-11f0-9ca4-2cf05da270f3">
<topic>Gitlab -- Vulnerabilities</topic>
<affects>