QID 731094
Date Published: 2024-01-23
QID 731094: Webmin Remote Command Execution Vulnerability (CVE-2022-35132)
Webmin is a powerful and flexible web-based server management control panel for Unix-like systems.
Usermin through 1.850 allows a remote authenticated user to execute OS commands via command injection in a filename for the GPG module.
Affected versions:
Webmin version upto 1.850
QID Detection Logic (Unauthenticated) :
This QID sends a HTTP GET request to the target application and determines vulnerable version of Webmin running based on the HTTP server header.
Successful exploitation of this vulnerability may allow attackers to execute arbitrary operating system commands remotely via command injection.
Solution
Customers are advised to upgrade to latest version of Webmin to remediate this vulnerability.
Vendor References
- Webmin Security Advisory -
webmin.com/tags/webmin-changelog/
CVEs related to QID 731094
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Webmin Downloads |
|