PT-2020-17415 · Webmin · Webmin
Published
2020-12-29
·
Updated
2022-07-17
·
CVE-2020-35769
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Webmin version 1.962
Description
The issue concerns the miniserv.pl component in Webmin, which mishandles special characters in query arguments to the CGI program. This can be exploited when sending queries to the
miniserv.pl CGI endpoint, potentially allowing for malicious actions due to the improper handling of special characters in query arguments.Recommendations
For Webmin version 1.962, consider disabling the miniserv.pl CGI program until a patch is available to prevent potential exploitation due to the mishandling of special characters in query arguments. Restrict access to the miniserv.pl component to minimize the risk of exploitation. Avoid using special characters in query arguments to the affected CGI program until the issue is resolved.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Webmin