CVE-2012-2983

medium
Published 2012-09-11 ยท Modified 2026-04-29
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
6.0

Description

file/edit_html.cgi in Webmin 1.590 and earlier does not perform an authorization check before showing a file's unedited contents, which allows remote attackers to read arbitrary files via the file field.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Exploits

Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.

Metasploit modules

Webmin edit_html.cgi file Parameter Traversal Arbitrary File Access
Source fetch failed: fetch_error โ€” view the original via the link above.

Application impact

VendorProductVersionsFixed
gentoo gentoowebmin{"endIncluding":"1.590"}
gentoo gentoowebmin1.140
gentoo gentoowebmin1.150
gentoo gentoowebmin1.160
gentoo gentoowebmin1.170
gentoo gentoowebmin1.180
gentoo gentoowebmin1.200
gentoo gentoowebmin1.210
gentoo gentoowebmin1.220
gentoo gentoowebmin1.230
gentoo gentoowebmin1.240
gentoo gentoowebmin1.260
gentoo gentoowebmin1.270
gentoo gentoowebmin1.280
gentoo gentoowebmin1.290
gentoo gentoowebmin1.300
gentoo gentoowebmin1.310
gentoo gentoowebmin1.320
gentoo gentoowebmin1.330
gentoo gentoowebmin1.340
gentoo gentoowebmin1.370
gentoo gentoowebmin1.380
gentoo gentoowebmin1.390
gentoo gentoowebmin1.400
gentoo gentoowebmin1.410
gentoo gentoowebmin1.420
gentoo gentoowebmin1.430
gentoo gentoowebmin1.440
gentoo gentoowebmin1.450
gentoo gentoowebmin1.470
gentoo gentoowebmin1.480
gentoo gentoowebmin1.500
gentoo gentoowebmin1.510
gentoo gentoowebmin1.520
gentoo gentoowebmin1.530
gentoo gentoowebmin1.550
gentoo gentoowebmin1.560
gentoo gentoowebmin1.570
gentoo gentoowebmin1.580

References

CWEs

CWE-287

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.