CVE-2022-30708: High severity webmin vulnerability
Published May 15, 2022
·Updated
Webmin through 1.991, when the Authentic theme is used, allows remote code execution when a user has been manually created (i.e., not created in Virtualmin or Cloudmin). This occurs because settings-editorwrite.cgi does not properly restrict the file parameter.
Affected Software
1 affected component
webmin webmin<=1.991
Remediation
Event History
May 15, 2022
CVE Published
via MITRE·02:30 AM
Data Sourced
via MITRE·02:30 AM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2022-30708?
CVE-2022-30708 is a vulnerability in Webmin through version 1.991 that allows remote code execution.
2
What is the severity of CVE-2022-30708?
The severity of CVE-2022-30708 is high, with a severity value of 8.8.
3
Which version of Webmin is affected by CVE-2022-30708?
Webmin versions up to and including 1.991 are affected by CVE-2022-30708.
4
How does CVE-2022-30708 allow remote code execution?
CVE-2022-30708 allows remote code execution when a user has been manually created in Webmin using the Authentic theme.
5
Is there a fix for CVE-2022-30708?
Yes, updating Webmin to a version beyond 1.991 can fix the CVE-2022-30708 vulnerability.