CVE-2017-15644 EXPLOIT
8.6
HIGH · CVSS 3.0 · EPSS 8.9% (pctl 95)
Patch early
A public exploit exists.
Description
SSRF exists in Webmin 1.850 via the PATH_INFO to tunnel/link.cgi, as demonstrated by a GET request for tunnel/link.cgi/http://INTRANET-IP:8000.
Scoring
| CVSS | 8.6 (HIGH, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
| EPSS | 8.93% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-918 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2017-10-19 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| webmin | webmin |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Webmin 1.850 - Multiple Vulnerabilities | 2017-10-15 |
References
- http://www.webmin.com/changes.html
- http://www.webmin.com/security.html
- https://blogs.securiteam.com/index.php/archives/3430
- https://github.com/webmin/webmin/commit/0c58892732ee7610a7abba5507614366d382c9c9
- http://www.webmin.com/changes.html
- http://www.webmin.com/security.html
- https://blogs.securiteam.com/index.php/archives/3430
- https://github.com/webmin/webmin/commit/0c58892732ee7610a7abba5507614366d382c9c9
→ the Explorer · watch your stack · NVD