CVE-2015-2079

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Apr 28, 2025
Updated: May 14, 2025
CWE ID 96
CWE ID 94

Summary

CVE-2015-2079 is a remote code execution vulnerability affecting Usermin versions 0.980 through 1.x before 1.660. This issue arises due to Usermin's use of the two-argument form of Perl open, which allows an attacker to free the sigfile descriptor, leading to arbitrary code execution via a specially crafted input. This vulnerability poses a significant risk to systems running the affected versions of Usermin and necessitates immediate patching.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share