PT-2026-40831 · Cpan · Web::Passwd
Robert Rothenberg
·
Published
2026-05-13
·
Updated
2026-05-15
·
CVE-2026-8500
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Web::Passwd version 0.03
Description
Web::Passwd, a small CGI application for managing htpasswd files via the htpasswd command, allows remote code execution. The
user parameter is not validated or escaped before being used as the final argument on the command line, which enables command injection.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Web::Passwd