Beveiligingsadvies

CVE-2022-30708

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2022-05-15 02:30:14
Laatst bijgewerkt 2024-08-03 06:56:13
Toegewezen door mitre
CVSS-score 8.8
Status PUBLISHED

Beschrijving

Webmin through 1.991, when the Authentic theme is used, allows remote code execution when a user has been manually created (i.e., not created in Virtualmin or Cloudmin). This occurs because settings-editor_write.cgi does not properly restrict the file parameter.