MFH: r509243 r509244
Update sysutils/webmin to version 1.930.
Contains fix for CVE-2019-15107.
From https://virtualmin.com/node/66890:
To exploit the malicious code, your Webmin installation must have Webmin -> Webmin Configuration -> Authentication -> Password expiry policy set to Prompt users with expired passwords to enter a new one. This option is not set by default, but if it is set, it allows remote code execution.
PR: 239956
Submitted by: Bert JW Regeer <xistence@0x58.com>
Security: CVE-2019-15107
Update sysutils/usermin to version 1.780.
PR: 239957
Approved by: ports-secteam (joneum)