漏洞描述
Webmin before 1.997 is susceptible to authenticated remote code execution via software/apt-lib.pl, which lacks HTML escaping for a UI command. An attacker can perform command injection attacks and thereby execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
medium.comhttps://medium.com/@emirpolat/cve-2022-36446-webmin-1-997-7a9225af3165↗github.comhttps://github.com/webmin/webmin/compare/1.996...1.997↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2022-36446↗packetstormsecurity.comhttp://packetstormsecurity.com/files/167894/Webmin-1.996-Remote-Code-Execution.html↗