An issue was discovered in Webmin 1.840 and 1.880 when the default Yes setting of "Can view any file as a log file" is enabled. As a result of weak default configuration settings, limited users have full access rights to the underlying Unix system files, allowing the user to read sensitive data from the local system (using Local File Include) such as the '/etc/shadow' file via a "GET /syslog/save_log.cgi?view=1&file=/etc/shadow" request.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWebmin
APPWebmin1.8401.880
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
Related vulnerabilities
CVE-2019-15107CRITICAL9.8⚠ KEVPL ✓same product
Command Injection w Webmin <=1.920 — nieautoryzowane RCE
CVE-2022-36446CRITICAL9.8PL ✓same product
Webmin – brak HTML escaping umożliwia RCE przez command injection
CVE-2021-32157CRITICAL9.6PL ✓same product
XSS w Webmin 1.973 — funkcja Scheduled Cron Jobs
CVE-2021-31761CRITICAL9.6PL ✓same product
Webmin 1.973 — reflected XSS prowadzący do Remote Command Execution
CVE-2020-35769CRITICAL9.8PL ✓same product
Webmin 1.962 (Windows): błędna obsługa znaków specjalnych w miniserv.pl