CVE-2022-35132: OS Command Injection
Published Oct 25, 2022
·Updated
Usermin through 1.850 allows a remote authenticated user to execute OS commands via command injection in a filename for the GPG module.
Affected Software
1 affected component
Webmin Usermin<=1.850
Event History
Oct 25, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2022-35132?
CVE-2022-35132 is a vulnerability in Usermin through version 1.850 that allows a remote authenticated user to execute OS commands via command injection in a filename for the GPG module.
2
How severe is CVE-2022-35132?
CVE-2022-35132 has a severity score of 8.8, which is classified as high.
3
What software versions are affected by CVE-2022-35132?
Usermin versions up to and including 1.850 are affected by CVE-2022-35132.
4
How can I fix CVE-2022-35132?
To fix CVE-2022-35132, users should update Usermin to a version higher than 1.850.
5
Where can I find more information about CVE-2022-35132?
More information about CVE-2022-35132 can be found at the following references: [link1], [link2].