Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users feature, and then get a reverse shell through Webmin's running process feature.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://github.com/webmin/webmin | third party advisory product |
https://youtu.be/qCvEXwyaF5U | third party advisory exploit |
https://github.com/Mesh3l911/CVE-2021-31762 | third party advisory exploit |
https://github.com/electronicbots/CVE-2021-31762 | third party advisory exploit |
http://packetstormsecurity.com/files/163492/Webmin-1.973-Cross-Site-Request-Forgery.html | exploit vdb entry third party advisory |