squid/cachemgr.cgi in Webmin before 2.600 does not properly quote arguments. This is relevant if Webmin's Squid module and its Cache Manager feature are available, and an untrusted party is able to authenticate to Webmin and has certain Cache Manager permissions (the "cms" security option).
References
Configurations
No configuration.
History
18 Dec 2025, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
11 Dec 2025, 07:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-11 07:16
Updated : 2025-12-18 14:16
NVD link : CVE-2025-67738
Mitre link : CVE-2025-67738
CVE.ORG link : CVE-2025-67738
JSON object : View
Products Affected
No product.
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
