CVE-2022-36446: Critical severity webmin vulnerability
Published Jul 25, 2022
·Updated
software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.
Affected Software
1 affected component
webmin webmin<1.997
Remediation
Event History
Jul 25, 2022
CVE Published
via MITRE·05:56 AM
Data Sourced
via MITRE·05:56 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-36446?
The severity of CVE-2022-36446 is critical with a CVSS score of 9.8.
2
What is the description of CVE-2022-36446?
CVE-2022-36446 is a vulnerability in software/apt-lib.pl in Webmin before version 1.997 that lacks HTML escaping for a UI command.
3
Which software versions are affected by CVE-2022-36446?
Webmin versions up to (but not including) 1.997 are affected by CVE-2022-36446.
4
How can I fix CVE-2022-36446?
To fix CVE-2022-36446, it is recommended to update Webmin to version 1.997 or later.
5
Where can I find more information about CVE-2022-36446?
Additional information about CVE-2022-36446 can be found at the following references: [1] [2] [3].