PT-2020-17415 · Webmin · Webmin

Published

2020-12-29

·

Updated

2022-07-17

·

CVE-2020-35769

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Webmin version 1.962
Description The issue concerns the miniserv.pl component in Webmin, which mishandles special characters in query arguments to the CGI program. This can be exploited when sending queries to the miniserv.pl CGI endpoint, potentially allowing for malicious actions due to the improper handling of special characters in query arguments.
Recommendations For Webmin version 1.962, consider disabling the miniserv.pl CGI program until a patch is available to prevent potential exploitation due to the mishandling of special characters in query arguments. Restrict access to the miniserv.pl component to minimize the risk of exploitation. Avoid using special characters in query arguments to the affected CGI program until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-35769

Affected Products

Webmin