CVE-2022-30708

Source
https://cve.org/CVERecord?id=CVE-2022-30708
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-30708.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-30708
Downstream
Published
2022-05-15T02:30:14Z
Modified
2026-07-15T01:48:50.015933002Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AC:L/AV:N/A:H/C:H/I:H/PR:L/S:U/UI:N CVSS Calculator
Summary
[none]
Details

Webmin through 1.991, when the Authentic theme is used, allows remote code execution when a user has been manually created (i.e., not created in Virtualmin or Cloudmin). This occurs because settings-editor_write.cgi does not properly restrict the file parameter.

Database specific
{
    "cna_assigner": "mitre",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/30xxx/CVE-2022-30708.json"
}
References

Affected packages

Git / github.com/webmin/webmin

Affected ranges

Type
GIT
Repo
https://github.com/webmin/webmin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "cpe": "cpe:2.3:a:webmin:webmin:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.991"
        }
    ],
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

1.*
1.700
1.710
1.720
1.730
1.740
1.750
1.760
1.770
1.780
1.790
1.800
1.801
1.810
1.820
1.830
1.831
1.840
1.850
1.860
1.870
1.880
1.890
1.900
1.910
1.920
1.930
1.940
1.941
1.950
1.951
1.953
1.954
1.955
1.960
1.962
1.970
1.972
1.973
1.974
1.980
1.982
1.983
1.984
1.990
1.991

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-30708.json"