Webmin · Webmin · CVE-2022-36446
**Name of the Vulnerable Software and Affected Versions**
Webmin versions prior to 1.997
**Description**
The issue is related to a lack of HTML escaping for a UI command in the software/apt-lib.pl component of Webmin, allowing a remote attacker to execute arbitrary code.
**Recommendations**
For versions prior to 1.997, update to version 1.997 or later to resolve the issue. As a temporary workaround, consider restricting access to the `software/apt-lib.pl` component until a patch is available.