SB2022031603 - Multiple vulnerabilities in Webmin
Published: March 16, 2022 Updated: November 8, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Improper access control (CVE-ID: CVE-2022-0824)
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions within the File Manager module. A remote user can bypass implemented security restrictions and compromise the affected system.
2) Improper Authorization (CVE-ID: CVE-2022-0829)
The vulnerability allows a remote user to compromise the affected system.
The vulnerability exists due to improper authorization in the File Manager module when using the default Authentic theme. A remote user can execute arbitrary code on the system.
Remediation
Install update from vendor's website.
References
- https://github.com/webmin/webmin/commit/39ea464f0c40b325decd6a5bfb7833fa4a142e38
- https://huntr.dev/bounties/d0049a96-de90-4b1a-9111-94de1044f295
- http://packetstormsecurity.com/files/166240/Webmin-1.984-Remote-Code-Execution.html
- https://huntr.dev/bounties/f2d0389f-d7d1-4f34-9f9d-268b0a0da05e
- https://github.com/webmin/webmin/commit/eeeea3c097f5cc473770119f7ac61f1dcfa671b9