CVE-2019-15107 | Webmin up to 1.920 password_change.cgi old command injection (ID 154141 / EDB-47230)
A vulnerability was found in Webmin up to 1.920. It has been declared as critical. This vulnerability affects unknown code of the file password_change.cgi. The manipulation of the argument old as part of Parameter leads to command injection.
This vulnerability was named CVE-2019-15107. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.