squid/cachemgr.cgi in Webmin before 2.600 does not properly quote arguments. This is relevant if Webmin's Squid module and its Cache Manager feature are available, and an untrusted party is able to authenticate to Webmin and has certain Cache Manager permissions (the "cms" security option).
Metrics
Affected Vendors & Products
References
History
Thu, 11 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 11 Dec 2025 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | squid/cachemgr.cgi in Webmin before 2.600 does not properly quote arguments. This is relevant if Webmin's Squid module and its Cache Manager feature are available, and an untrusted party is able to authenticate to Webmin and has certain Cache Manager permissions. | squid/cachemgr.cgi in Webmin before 2.600 does not properly quote arguments. This is relevant if Webmin's Squid module and its Cache Manager feature are available, and an untrusted party is able to authenticate to Webmin and has certain Cache Manager permissions (the "cms" security option). |
| First Time appeared |
Webmin
Webmin webmin |
|
| CPEs | cpe:2.3:a:webmin:webmin:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Webmin
Webmin webmin |
Thu, 11 Dec 2025 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | squid/cachemgr.cgi in Webmin before 2.600 does not properly quote arguments. This is relevant if Webmin's Squid module and its Cache Manager feature are available, and an untrusted party is able to authenticate to Webmin and has certain Cache Manager permissions. | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-12-11T06:34:10.060Z
Updated: 2025-12-11T14:58:30.433Z
Reserved: 2025-12-11T06:34:09.826Z
Link: CVE-2025-67738
Updated: 2025-12-11T14:58:03.294Z
Status : Awaiting Analysis
Published: 2025-12-11T07:16:00.887
Modified: 2025-12-12T15:18:13.390
Link: CVE-2025-67738
No data.