← back
CVE-2024-12828criticalCWE-78

Webmin CGI Command Injection Remote Code Execution Vulnerability

60Vexday Risk Score

Keep watching. It has a public proof of concept.

ssvc Attendcvss 9.9epss 33%
from disclosure to weapon340 days
Published on NVDDec 30
1st PoC+340d
exploitation probability
33%top 2% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Webmin CGI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Webmin. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of CGI requests. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-22346.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products
Webmin · Webmin
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.