esp0xdeadbeef/rce_webmin

esp0xdeadbeef/rce_webmin

Releases0
Stars7
RCE and privilege escalation webmin version 1.991

CVE History

CVEPublishedCVSS v3CVSS v2
8.8 HIGH6.5 MEDIUM

Webmin through 1.991, when the Authentic theme is used, allows remote code execution when a user has been manually created (i.e., not created in Virtualmin or Cloudmin). This occurs because settings-editor_write.cgi does not properly restrict the file parameter.