CVE-2012-2983: Gentoo Webmin
Medium severity, CVSS 5.0. EPSS: 20.5% chance of exploitation in the next 30 days.
file/edit_html.cgi in Webmin 1.590 and earlier does not perform an authorization check before showing a file's unedited contents, which allows remote attackers to read arbitrary files via the file field.
Affected products
- Gentoo Webmin: up to and including 1.590; version 1.140 only; version 1.150 only; version 1.160 only; version 1.170 only; version 1.180 only; …
Published 2012-09-11. Last modified 2026-06-16.