CVE-2022-0824

HIGH NUCLEI

Webmin < 1.990 - Incorrect Authorization

Title source: rule

Description

Improper Access Control to Remote Code Execution in GitHub repository webmin/webmin prior to 1.990.

Exploits (7)

nomisec WORKING POC 111 stars
by faisalfs10x · poc
https://github.com/faisalfs10x/Webmin-CVE-2022-0824-revshell
nomisec WRITEUP 4 stars
by honypot · poc
https://github.com/honypot/CVE-2022-0824
nomisec WORKING POC 3 stars
by pizza-power · poc
https://github.com/pizza-power/golang-webmin-CVE-2022-0824-revshell
nomisec WORKING POC
by NUDTTAN91 · poc
https://github.com/NUDTTAN91/Webmin-CVE-2022-0824-Enhanced-Exploit
nomisec WORKING POC
by gokul-ramesh · poc
https://github.com/gokul-ramesh/WebminRCE-exploit
metasploit WORKING POC EXCELLENT
by faisalfs10x, jheysel-r7 · rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/webmin_file_manager_rce.rb
exploitdb WORKING POC
by faisalfs10x · pythonwebappslinux
https://www.exploit-db.com/exploits/50809

Nuclei Templates (1)

Webmin <1.990 - Improper Access Control
HIGHby cckuailong
Shodan: http.title:"webmin"
FOFA: title="webmin"

Scores

CVSS v3 8.8
EPSS 0.9388
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-284 CWE-863
Status published

Affected Products (1)

webmin/webmin < 1.990

Timeline

Published Mar 02, 2022
Tracked Since Feb 18, 2026