• Tenable
  • CVEs
  • Settings
    Links
    Tenable.io Tenable Community & Support Tenable University
    Severity
    Theme
  • Tenable
  • Links
  • Tenable.io
  • Tenable Community & Support
  • Tenable University
  • Settings
  • Severity
  • Theme
  • Newest
  • Updated
  • Search
  • Newest
  • Updated
  • Search
  1. CVEs
  2. CVE-2022-36446
  1. CVEs

CVE-2022-36446

critical
  • Information
  • CPEs
  • Plugins

Description

software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.

References

https://github.com/webmin/webmin/compare/1.996...1.997

https://github.com/webmin/webmin/commit/13f7bf9621a82d93f1e9dbd838d1e22020221bde

http://packetstormsecurity.com/files/167894/Webmin-1.996-Remote-Code-Execution.html

https://www.exploit-db.com/exploits/50998

https://gist.github.com/emirpolatt/cf19d6c0128fa3e25ebb47e09243919b

http://packetstormsecurity.com/files/168049/Webmin-Package-Updates-Command-Injection.html

Details

Source: MITRE

Published: 2022-07-25

Updated: 2022-10-06

Type: CWE-116

  • Tenable.com
  • Community & Support
  • Documentation
  • Education
  • © 2023 Tenable®, Inc. All Rights Reserved
  • Privacy Policy
  • Legal
  • 508 Compliance