QID 730680

Date Published: 2023-01-05

QID 730680: Webmin Multiple Vulnerabilities

Webmin is a web-based interface for system administration for Unix, although recent versions can also be installed and run on Windows.

Affected Versions:
Webmin versions 1.973 .

QID Detection Logic:
This QID sends specially crafted GET/POST request to check if the target is vulnerable or not.

Successful exploitation of these vulnerabilities may allow an attacker with sufficient privileges to escalate to root and gain access to unauthorized data.

  • CVSS V3 rated as Critical - 9.6 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    For more information visit Webmin Security Advisory.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    CVE-2021-32156,CVE-2021-32157,CVE-2021-32159,CVE-2021-32162 URL Logo www.webmin.com/security.html