PT-2025-18077 · Usermin · Usermin
Published
2025-04-28
·
Updated
2025-05-14
·
CVE-2015-2079
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Usermin versions 0.980 through 1.x before 1.660
Description
The issue allows remote code execution in uconfig save.cgi due to the use of the two-argument form of Perl
open(). This affects Usermin, potentially allowing unauthorized access and code execution.Recommendations
For versions 0.980 through 1.x before 1.660, consider disabling the
uconfig save.cgi script until a patch is available to prevent remote code execution. Restrict access to the sig file free function to minimize the risk of exploitation. Avoid using the vulnerable open() function in Perl scripts until the issue is resolved.Exploit
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Usermin