CVE-2012-4893

medium
Published 2012-09-11 · Modified 2026-04-29
CVSS v3
CVSS v2
6.8
VIR risk
6.8

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in file/show.cgi in Webmin 1.590 and earlier allow remote attackers to hijack the authentication of privileged users for requests that (1) read files or execute (2) tar, (3) zip, or (4) gzip commands, a different issue than CVE-2012-2982.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

Application impact

VendorProductVersionsFixed
gentoowebmin{"endIncluding":"1.590"}
gentoowebmin1.140
gentoowebmin1.150
gentoowebmin1.160
gentoowebmin1.170
gentoowebmin1.180
gentoowebmin1.200
gentoowebmin1.210
gentoowebmin1.220
gentoowebmin1.230
gentoowebmin1.240
gentoowebmin1.260
gentoowebmin1.270
gentoowebmin1.280
gentoowebmin1.290
gentoowebmin1.300
gentoowebmin1.310
gentoowebmin1.320
gentoowebmin1.330
gentoowebmin1.340
gentoowebmin1.370
gentoowebmin1.380
gentoowebmin1.390
gentoowebmin1.400
gentoowebmin1.410
gentoowebmin1.420
gentoowebmin1.430
gentoowebmin1.440
gentoowebmin1.450
gentoowebmin1.470
gentoowebmin1.480
gentoowebmin1.500
gentoowebmin1.510
gentoowebmin1.520
gentoowebmin1.530
gentoowebmin1.550
gentoowebmin1.560
gentoowebmin1.570
gentoowebmin1.580

References

CWEs

CWE-352

Verify integrity in audit chain (admin only). AS-IS.