Webmin <=1.920. is vulnerable to an unauthenticated remote command execution via the parameter ‘old’ in password_change.cgi.
View the template here CVE-2019-15107.yaml
References:
http://packetstormsecurity.com/files/154485/Webmin-1.920-Remote-Code-Execution.html