HIGH

CVE-2019-9624

CVSS v3

7.8

HIGH

EPSS Score

52.5%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Webmin 1.900 allows remote attackers to execute arbitrary code by leveraging the "Java file manager" and "Upload and Download" privileges to upload a crafted .cgi file via the /updown/upload.cgi URI.

Technical details

Published
3/7/2019

Frequently asked questions

What is CVE-2019-9624?

Webmin 1.900 allows remote attackers to execute arbitrary code by leveraging the "Java file manager" and "Upload and Download" privileges to upload a crafted .cgi file via the /updown/upload.cgi URI.

Is CVE-2019-9624 actively exploited?

Active exploitation of CVE-2019-9624 has not been confirmed. The EPSS score is 52.5%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2019-9624?

CVE-2019-9624 has a CVSS v3 base score of 7.8 (HIGH severity).

Is CVE-2019-9624 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.