QID 150563
Date Published: 2022-08-30
QID 150563: Webmin Authenticated Command Injection Vulnerability (CVE-2022-36446)
Webmin is a powerful and flexible web-based server management control panel for Unix-like systems.
In affected versions of Webmin, software/apt-lib.pl before version 1.997 lacks HTML escaping for a UI command leading to Command Injection Vulnerability.
Affected versions:
Webmin versions prior to 1.997
QID Detection Logic (Unauthenticated) :
This QID sends a HTTP GET request to the target application and determines vulnerable version of Webmin running based on the HTTP server header.
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the target system.
Solution
Customers are advised to upgrade to latest version of Webmin to remediate this vulnerability.
Vendor References
CVEs related to QID 150563
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Webmin Downloads |
|