Description

squid/cachemgr.cgi in Webmin before 2.600 does not properly quote arguments. This is relevant if Webmin's Squid module and its Cache Manager feature are available, and an untrusted party is able to authenticate to Webmin and has certain Cache Manager permissions (the "cms" security option).

INFO

Published Date :

2025-12-11T06:34:10.060Z

Last Modified :

2025-12-18T13:59:22.457Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2025-67738 vulnerability.

Vendors Products
Webmin
  • Webmin

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact