squid/cachemgr.cgi in Webmin before 2.600 does not properly quote arguments....
Vulnerability Description
squid/cachemgr.cgi in Webmin before 2.600 does not properly quote arguments. This is relevant if Webmin's Squid module and its Cache Manager feature are available, and an untrusted party is able to authenticate to Webmin and has certain Cache Manager permissions (the "cms" security option).
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-67738
Credits & Attribution
No credits recorded in the NVD database.
References
More from Webmin
View All →Affected Vendor
Webmin
View all reports →