CVE-2025-67738

squid/cachemgr.cgi in Webmin before 2.600 does not properly quote arguments. This is relevant if Webmin's Squid module and its Cache Manager feature are available, and an untrusted party is able to authenticate to Webmin and has certain Cache Manager permissions (the "cms" security option).
Configurations

No configuration.

History

18 Dec 2025, 14:16

Type Values Removed Values Added
References
  • () https://webmin.com/security/#privilige-escalation-using-squid-module-cve-2025-67738 -

11 Dec 2025, 07:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-11 07:16

Updated : 2025-12-18 14:16


NVD link : CVE-2025-67738

Mitre link : CVE-2025-67738

CVE.ORG link : CVE-2025-67738


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')