Critical severity9.8NVD Advisory· Published Jul 25, 2022· Updated Jun 17, 2026
CVE-2022-36446
CVE-2022-36446
Description
software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
6- github.com/webmin/webmin/commit/13f7bf9621a82d93f1e9dbd838d1e22020221bdenvdPatchThird Party Advisory
- packetstormsecurity.com/files/168049/Webmin-Package-Updates-Command-Injection.htmlnvdExploitThird Party AdvisoryVDB Entry
- gist.github.com/emirpolatt/cf19d6c0128fa3e25ebb47e09243919bnvdExploitThird Party Advisory
- packetstormsecurity.com/files/167894/Webmin-1.996-Remote-Code-Execution.htmlnvdThird Party AdvisoryVDB Entry
- github.com/webmin/webmin/compare/1.996...1.997nvdRelease NotesThird Party Advisory
- www.exploit-db.com/exploits/50998nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.