{"id":"CVE-2022-36446","aliases":[],"url":"https://o3.security/vulnerability/CVE-2022-36446","summary":null,"details":"software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.","published":"2022-07-25T05:56:47Z","modified":"2026-08-12T03:51:09.577252586Z","cvss":null,"epss":{"score":0.96049,"percentile":0.99873,"asOf":"2026-08-21"},"cisaKev":null,"exploitsKnown":8,"affectedPackages":[],"fix":{"url":"https://github.com/webmin/webmin/commit/13f7bf9621a82d93f1e9dbd838d1e22020221bde","label":"webmin/webmin@13f7bf9"},"references":[{"type":"WEB","url":"http://packetstormsecurity.com/files/167894/Webmin-1.996-Remote-Code-Execution.html"},{"type":"WEB","url":"http://packetstormsecurity.com/files/168049/Webmin-Package-Updates-Command-Injection.html"},{"type":"WEB","url":"https://gist.github.com/emirpolatt/cf19d6c0128fa3e25ebb47e09243919b"},{"type":"WEB","url":"https://github.com/webmin/webmin/compare/1.996...1.997"},{"type":"WEB","url":"https://www.exploit-db.com/exploits/50998"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/36xxx/CVE-2022-36446.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-36446"},{"type":"FIX","url":"https://github.com/webmin/webmin/commit/13f7bf9621a82d93f1e9dbd838d1e22020221bde"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:09.577252586Z"}}