CVE-2024-12828
HIGHWebmin - Authenticated Remote Code Execution via CGI Request Handling
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-12828. PoCs published by fanjm2025-jeremy.
AI-analyzed exploit summary This repository contains a functional Python exploit for CVE-2024-12828, a Webmin CGI command injection vulnerability. The exploit sends a crafted POST request with a reverse shell payload to achieve remote code execution on the target system.
Description
Webmin CGI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Webmin. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of CGI requests. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-22346.
Exploits (1)
This repository contains a functional Python exploit for CVE-2024-12828, a Webmin CGI command injection vulnerability. The exploit sends a crafted POST request with a reverse shell payload to achieve remote code execution on the target system.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H