CVE-2022-0824
02.03.2022, 12:15
Improper Access Control to Remote Code Execution in GitHub repository webmin/webmin prior to 1.990.Enginsight
Vendor | Product | Version |
---|---|---|
webmin | webmin | 𝑥 < 1.990 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-284 - Improper Access ControlThe software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
- CWE-863 - Incorrect AuthorizationThe software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
References