CVE-2022-0829
published 2022-03-02CVE-2022-0829: Improper Authorization in GitHub repository webmin/webmin prior to 1.990.
PriorityP339high8.1CVSS 3.1
AVNACLPRLUINSUCNIHAH
EPSS
1.27%
66.3th percentile
Improper Authorization in GitHub repository webmin/webmin prior to 1.990.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| webmin | webmin | < 1.990 | 1.990 |
| webmin | webmin_webmin | >= unspecified < 1.990 | 1.990 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/webmin/webmin/commit/eeeea3c097f5cc473770119f7ac61f1dcfa671b9https://huntr.dev/bounties/f2d0389f-d7d1-4f34-9f9d-268b0a0da05ehttps://notes.netbytesec.com/2022/03/webmin-broken-access-control-to-post-auth-rce.htmlhttps://github.com/webmin/webmin/commit/eeeea3c097f5cc473770119f7ac61f1dcfa671b9https://huntr.dev/bounties/f2d0389f-d7d1-4f34-9f9d-268b0a0da05ehttps://notes.netbytesec.com/2022/03/webmin-broken-access-control-to-post-auth-rce.html
2022-03-02
Published