CVE-2022-36446

CRITICAL NUCLEI

Webmin <1.997 - XSS

Title source: llm

Description

software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.

Exploits (5)

exploitdb WORKING POC
by Emir Polat · pythonwebappslinux
https://www.exploit-db.com/exploits/50998
nomisec WORKING POC 116 stars
by p0dalirius · poc
https://github.com/p0dalirius/CVE-2022-36446-Webmin-Software-Package-Updates-RCE
nomisec WORKING POC 2 stars
by emirpolatt · poc
https://github.com/emirpolatt/CVE-2022-36446
nomisec WORKING POC
by Kang3639 · poc
https://github.com/Kang3639/CVE-2022-36446
metasploit WORKING POC EXCELLENT
by Christophe De La Fuente, Emir Polat · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/webmin_package_updates_rce.rb

Nuclei Templates (1)

Webmin <1.997 - Authenticated Remote Code Execution
CRITICALby gy741
Shodan: title:"Webmin" || http.title:"webmin"
FOFA: title="webmin"

Scores

CVSS v3 9.8
EPSS 0.9293
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-116
Status published
Products (1)
webmin/webmin < 1.997
Published Jul 25, 2022
Tracked Since Feb 18, 2026