S4E just found a high-severity finding from cve-2026-42945 scanner (version based)
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-36446 Scanner

Detects 'Remote Code Execution (RCE)' vulnerability in Webmin affects v. before 1.997.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.1k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-36446
9.8
CVSS

software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Webmin is a powerful web-based server administration tool used by organizations of all sizes to manage their Linux systems. It provides a user-friendly interface that allows users to manage various aspects of their server, monitoring system processes, managing user accounts, configuring network settings, and much more. Webmin simplifies and streamlines the management of servers by providing an easy-to-use interface accessible from any web-enabled device.

CVE-2022-36446 is a vulnerability detected in the software/apt-lib.pl file in Webmin before version 1.997. This vulnerability is due to a lack of HTML escaping for a user interface (UI) command. As a result, an attacker can easily inject malicious code into the UI command, which can be executed on the target server. A successful exploit can lead to the complete compromise of the vulnerable system, allowing attackers to carry out a range of malicious activities.

When exploited, the vulnerability can lead to a number of potentially devastating consequences to the affected system. Attackers can gain access to sensitive information, such as login credentials, financial data, and intellectual property. They can also use the compromised system to launch further attacks against other systems on the network, potentially leading to extensive damage to the organization and its stakeholders.

As part of the s4e.io platform, users can easily access comprehensive reports on the vulnerabilities in their digital assets. The platform provides advanced features to detect and report on potential threats, allowing users to quickly identify and remediate vulnerabilities before they can be exploited. With the help of s4e.io's pro features, users can secure their digital assets and protect their organizations against malicious attacks.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users can take the following precautions:

  • Update Webmin to the latest version that includes a fix for the vulnerability.
  • Restrict access to Webmin to authorized users only.
  • Monitor the network traffic to identify any unusual activity that may indicate an attack.
  • Regularly review system logs to identify any suspicious activity.
  • Implement a robust backup and recovery strategy to mitigate the impact of any successful attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.