Improper Access Control to Remote Code Execution in webmin/webmin
83Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 8.3epss 97%
from disclosure to weapon4 days
Published on NVDMar 2
1st PoC+4d
metasploitFeb 26
exploitation probability
97%top 1% of all CVEs
observed exploitation
nono source reports it
7 public exploit(s)
Improper Access Control to Remote Code Execution in GitHub repository webmin/webmin prior to 1.990.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Affected products
webmin · webmin/webminpublic PoCs found — 7
exploitdbwww.exploit-db.com/exploits/50809unverifiedgithubgithub.com/faisalfs10x/Webmin-CVE-2022-0824-revshell★ 111githubgithub.com/pizza-power/golang-webmin-CVE-2022-0824-revshell★ 3githubgithub.com/gokul-ramesh/WebminRCE-exploit★ 0githubgithub.com/NUDTTAN91/Webmin-CVE-2022-0824-Enhanced-Exploit★ 0cve_referencepacketstormsecurity.com/files/166240/Webmin-1.984-Remote-Code-Execution.htmlunverifiedcve_referencepacketstormsecurity.com/files/169700/Webmin-1.984-File-Manager-Remote-Code-Execution.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/166240/Webmin-1.984-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/169700/Webmin-1.984-File-Manager-Remote-Code-Execution.htmlhttps://github.com/webmin/webmin/commit/39ea464f0c40b325decd6a5bfb7833fa4a142e38https://huntr.dev/bounties/d0049a96-de90-4b1a-9111-94de1044f295https://notes.netbytesec.com/2022/03/webmin-broken-access-control-to-post-auth-rce.html