CVE-2022-30708
Webmin vulnerability analysis and mitigation

Overview

CVE-2022-30708 affects Webmin through version 1.991 when using the Authentic theme. The vulnerability allows remote code execution when a user has been manually created (not created in Virtualmin or Cloudmin). This security flaw was discovered and reported on May 14, 2022, and stems from the settings-editor_write.cgi script not properly restricting the file parameter (NVD, CVE).

Technical details

The vulnerability has a CVSS v3.1 base score of 8.8 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. The issue specifically occurs in the settings-editor_write.cgi script where insufficient restrictions on the file parameter allow for arbitrary file writes. This can lead to remote code execution when exploited by a manually created user with access to the Authentic theme (NVD).

Impact

When successfully exploited, this vulnerability allows an attacker with a manually created user account to execute arbitrary code on the system with elevated privileges. This could potentially lead to complete system compromise, as the attacker can gain unauthorized access to sensitive data and perform privileged operations (NVD).

Mitigation and workarounds

The vulnerability was addressed through a security patch. Users should upgrade their Webmin installation to a version newer than 1.991. The fix includes proper restrictions on the file parameter in the settings-editor_write.cgi script (Webmin Commit).

Community reactions

The vulnerability was initially reported through GitHub issues, where it was promptly acknowledged and addressed by the Webmin development team. The discovery was made during a live streaming session, which garnered attention from the security research community (GitHub Issue).

Additional resources


SourceThis report was generated using AI

Related Webmin vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-12828HIGH8.8
  • WebminWebmin
  • cpe:2.3:a:webmin:webmin
NoYesDec 30, 2024
CVE-2025-67738HIGH8.5
  • WebminWebmin
  • cpe:2.3:a:webmin:webmin
NoYesDec 11, 2025
CVE-2024-45692HIGH7.5
  • WebminWebmin
  • cpe:2.3:a:webmin:webmin
NoYesSep 04, 2024
CVE-2025-61541HIGH7.1
  • WebminWebmin
  • cpe:2.3:a:webmin:webmin
NoYesOct 16, 2025
CVE-2024-36453MEDIUM6.1
  • WebminWebmin
  • cpe:2.3:a:webmin:webmin
NoYesJul 10, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management