Cross-site request forgery in Webmin - CVE-2021-31762
Published: April 26, 2021 / Updated: November 25, 2021
Vulnerability details
The vulnerability allows a remote attacker to perform cross-site request forgery attacks.
The vulnerability exists due to insufficient validation of the HTTP request origin within the add users feature. A remote attacker can trick the victim to visit a specially crafted web page and perform arbitrary actions on behalf of the victim on the vulnerable website, such as create a privileged user account.
Affected software
How to mitigate CVE-2021-31762
Links to Public Exploits and PoC-codes
- Exploit #7078 - Webmin 1.973 - Cross-Site Request Forgery (CSRF) (November 25, 2021)
- Exploit #5325 - CVE-2021-31762 (Exploiting a Cross-site request forgery (CSRF) attack to creat a new privileged user through the Webmin's add users feature) (April 28, 2021)
- Exploit #5323 - CVE-2021-31762 (Exploiting a Cross-site request forgery (CSRF) attack to creat a new privileged user through the Webmin's add users feature ) (April 28, 2021)