CVE-2019-15642 – Authenticated RCE on Webmin <= 1.920

CVE-2019-15642 – Authenticated RCE on Webmin <= 1.920

Rpc.cgi After the XXE, we found another bug in Webmin. This time it’s rpc.cgi which is vulnerable. More precisely a call to “unserialise_variable” function is done before than...
Published on: Jul 31 2019
By: Loïc
1 Comment