CVE-2015-2079: Webmin Usermin
High severity, CVSS 8.8. EPSS: 1.5% chance of exploitation in the next 30 days.
Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the two argument (not three argument) form of Perl open.
Affected products
- Webmin Usermin: from 0.980, before 1.660 (fixed in 1.660)
Published 2025-04-28. Last modified 2026-06-17.