8.8
CVSSv3

CVE-2021-31762

Published: 25/04/2021 Updated: 08/12/2021
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 606
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users feature, and then get a reverse shell through Webmin's running process feature.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

webmin webmin 1.973

Exploits

Webmin version 1973 suffers from a cross site request forgery vulnerability ...

Github Repositories

Exploiting a Cross-site request forgery (CSRF) attack to creat a new privileged user through the Webmin's add users feature

CSRF-to-RCE | CVE-2021-31762 | Description : Exploiting a Cross-site request forgery (CSRF) attack to create a privileged user through the Webmin's add users feature then getting a reverse shell through the Webmin's running process feature Tested Version : Webmin 1973 ( GitHub's latest version 07/03/2021 ) Attack Type: Remote Impact : Remote Command Exe

Exploiting a Cross-site request forgery (CSRF) attack to creat a new privileged user through the Webmin's add users feature

| CVE-2021-31762 | Description : Exploiting a Cross-site request forgery (CSRF) attack to create a privileged user through the Webmin's add users feature then getting a reverse shell through the Webmin's running process feature Tested Version : Webmin 1973 ( GitHub's latest version 07/03/2021 ) Attack Type: Remote Impact : Remote Command Execution eXp