CVE-2021-32157
CRITICALWebmin 1.973 - Stored Cross-Site Scripting via Scheduled Cron Jobs Feature
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2021-32157. PoCs published by dnr6419, Mesh3l911.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2021-32157, a vulnerability in Webmin 1.973 that allows remote code execution via a CSRF attack on the cron job feature. The exploit generates a malicious link that, when visited by an authenticated admin, executes a reverse shell payload.
Description
A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.
Exploits (2)
This repository contains a functional exploit for CVE-2021-32157, a vulnerability in Webmin 1.973 that allows remote code execution via a CSRF attack on the cron job feature. The exploit generates a malicious link that, when visited by an authenticated admin, executes a reverse shell payload.
This repository contains a functional exploit for CVE-2021-32157, which chains a reflected XSS vulnerability in Webmin to achieve remote command execution via cron job manipulation. The exploit generates a malicious link that, when visited by an authenticated admin, triggers a reverse shell.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H