漏洞描述
Webmin before 1.990 is susceptible to improper access control in GitHub repository webmin/webmin. This in turn can lead to remote code execution, by which an attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
github.comhttps://github.com/faisalfs10x/Webmin-CVE-2022-0824-revshell/blob/main/Webmin-revshell.py↗github.comhttps://github.com/webmin/webmin/commit/39ea464f0c40b325decd6a5bfb7833fa4a142e38↗huntr.devhttps://huntr.dev/bounties/d0049a96-de90-4b1a-9111-94de1044f295↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2022-0824↗