xmlrpc.cgi in Webmin up to and including 1.930 allows authenticated XXE attacks. By default, only root, admin, and sysadm can access xmlrpc.cgi.
webmin webmin