CVE-2015-2079
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Apr 28, 2025
Updated: May 14, 2025
CWE ID 96
CWE ID 94
Summary
CVE-2015-2079 is a remote code execution vulnerability affecting Usermin versions 0.980 through 1.x before 1.660. This issue arises due to Usermin's use of the two-argument form of Perl open, which allows an attacker to free the sigfile descriptor, leading to arbitrary code execution via a specially crafted input. This vulnerability poses a significant risk to systems running the affected versions of Usermin and necessitates immediate patching.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- The Webmin Community