CVE-2022-36446 is a vulnerability in Webmin prior to version 1.997, specifically in the software/apt-lib.pl component, where user input is not properly HTML-escaped in a UI command. This lack of proper escaping can allow for the injection of malicious HTML or JavaScript code into the Webmin interface, leading to a cross-site scripting (XSS) condition. The vulnerability requires authentication to exploit, as the affected UI command is only accessible to authenticated users.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository is a small standalone exploit for CVE-2022-36446 affecting Webmin versions earlier than 1.997. It contains two files: a README with usage instructions and one Python exploit script. The script uses `requests` and `BeautifulSoup` to authenticate to Webmin over port 10000, verify login success via `/sysinfo.cgi`, check whether the authenticated user can access the `package-updates` module, and then submit a malicious request to `/package-updates/update.cgi`. The exploit abuses insufficient sanitization of the `u` parameter in the Software Package Updates module to inject a shell command. Its payload is a hardcoded Python3 reverse shell that connects back to an attacker-supplied IP and port and spawns `/bin/sh`. The exploit is authenticated, requires module access, disables TLS certificate verification, and is intended for direct operational use rather than mere detection. The repository is minimal but functional: `README.md` documents prerequisites and execution steps, while `exploit.py` implements the full attack flow from login to exploitation.
This repository contains a single Metasploit module targeting a remote command injection vulnerability (CVE-2022-36446) in Webmin versions prior to 1.997. The exploit abuses insufficient input sanitization in the Software Package Updates module, allowing authenticated users to inject arbitrary commands into package manager operations. The module requires valid credentials for a user with access to the affected module. It supports multiple payloads, including in-memory command execution and Meterpreter reverse shells for x86, x64, and ARM64 Linux systems. The exploit interacts with the Webmin web interface over HTTPS (default port 10000), specifically targeting the /session_login.cgi endpoint for authentication and /package-updates/update.cgi for exploitation. The code is mature, weaponized, and part of the Metasploit framework, making it easy to use and customize for post-exploitation activities.
This repository provides a Python exploit script (CVE-2022-36446.py) targeting CVE-2022-36446, an authenticated remote code execution vulnerability in Webmin versions prior to 1.997. The exploit requires valid Webmin credentials and leverages a command injection flaw in the Software Package Updates module, specifically via the 'u' parameter in POST requests to /package-updates/update.cgi. The script supports both single command execution and an interactive shell mode. The repository also includes a Dockerfile and Makefile under test_env/ to facilitate local testing with a vulnerable Webmin 1.996 instance. The README provides usage instructions, mitigation advice (update to Webmin >= 1.997), and references. The main attack vector is network-based, requiring HTTP(S) access to the target Webmin instance. The exploit is operational, providing real RCE capabilities for authenticated users.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.