CVE-2022-0824 is an improper access-control vulnerability in the Webmin File Manager module affecting versions prior to 1.990. An authenticated low-privilege user who lacks File Manager permissions can nevertheless access secondary File Manager functionality. By chaining remote file retrieval with permission-changing functionality, the attacker can place a crafted CGI program, make it executable, and trigger remote command execution as root.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains an enhanced exploit for CVE-2022-0824, a critical remote code execution vulnerability in Webmin versions prior to 1.990. The exploit is implemented in a single Python script (exploit.py) and supports two main attack modes: direct command execution and reverse shell. The attacker provides the target Webmin URL, valid credentials, and (optionally) a shell command or reverse shell callback parameters. The script generates unique CGI payloads in Perl, Bash, or Python, uploads them to the target via the Webmin file manager, and triggers their execution. The exploit features robust file management, automatic cleanup of old payloads, and detailed logging. The README provides comprehensive usage instructions, parameter explanations, and security recommendations. The main attack vector is network-based, targeting the Webmin management interface over HTTP(S). The exploit is operational and can be used for both proof-of-concept and practical exploitation in authorized security testing scenarios.
This repository contains a single Metasploit module exploit targeting Webmin version 1.984 on Linux (CVE-2022-0824). The exploit leverages a vulnerability that allows any authenticated user (even without File Manager access) to abuse file manager functionalities to upload and execute a malicious CGI payload, resulting in remote code execution. The module automates the process: it logs in with provided credentials, uses the File Manager's HTTP endpoints to download a payload from the attacker's HTTP server, modifies its permissions, and executes it to establish a reverse shell. The exploit is weaponized, supporting customizable payloads via the Metasploit framework. The main file is written in Ruby and follows standard Metasploit module structure, with clear separation of functions for each exploitation step. Key fingerprintable endpoints include the Webmin File Manager CGI scripts and the path where the payload is stored and executed.
This repository contains a Python exploit script (Webmin-revshell.py) targeting Webmin versions 1.984 and below, specifically exploiting CVE-2022-0824 and CVE-2022-0829. The exploit leverages improper access control in the File Manager module, allowing a less privileged authenticated user to upload and execute a reverse shell with root privileges. The script automates the process: it generates a Perl reverse shell payload, logs into the target Webmin instance, hosts a local HTTP server to serve the payload, uses Webmin's file manager endpoints to download and set permissions on the payload, and finally executes it to establish a reverse shell connection to the attacker's machine. The repository includes a README with detailed usage instructions and a .gitignore file. The main exploit logic is contained in a single Python file, which interacts with several Webmin HTTP endpoints and requires attacker-controlled infrastructure (HTTP server and listener). The exploit is operational and provides a working reverse shell if the target is vulnerable and properly configured.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.