CVE-2012-2983: Gentoo Webmin

Medium severity, CVSS 5.0. EPSS: 20.5% chance of exploitation in the next 30 days.

file/edit_html.cgi in Webmin 1.590 and earlier does not perform an authorization check before showing a file's unedited contents, which allows remote attackers to read arbitrary files via the file field.

Affected products

  • Gentoo Webmin: up to and including 1.590; version 1.140 only; version 1.150 only; version 1.160 only; version 1.170 only; version 1.180 only; …

Published 2012-09-11. Last modified 2026-06-16.