VYPR

Authentic Theme

by Webmin

CVEs (1)

  • CVE-2022-30708HigMay 15, 2022
    risk 0.00cvss 8.8epss 0.04

    Webmin through 1.991, when the Authentic theme is used, allows remote code execution when a user has been manually created (i.e., not created in Virtualmin or Cloudmin). This occurs because settings-editor_write.cgi does not properly restrict the file parameter.