QID 730500

Date Published: 2022-05-25

QID 730500: Webmin Privilege Escalation Vulnerability

Webmin is a web-based interface for system administration for Unix, although recent versions can also be installed and run on Windows.

Affected Versions:
Webmin versions 1.991 and prior

QID Detection Logic:
This QID sends specially crafted GET/POST request to check if the target is vulnerable or not.

Successful exploitation of these vulnerabilities may allow an attacker with sufficient privileges to escalate to root and gain access to unauthorized data.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution
    For more information visit Webmin Security Advisory.
    Vendor References

    CVEs related to QID 730500

    Software Advisories
    Advisory ID Software Component Link
    CVE-2022-30708 URL Logo www.webmin.com/security.html