CVE-2025-61541Disclosure(webmin / webmin)

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Webmin 2.510 is vulnerable to a Host Header Injection in the password reset functionality (forgot_send.cgi). The reset link sent to users is constructed using the HTTP Host header via get_webmin_email_url(). An attacker can manipulate the Host header to inject a malicious domain into the reset email. If a victim follows the poisoned link, the attacker can intercept the reset token and gain full control of the target account.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • webmin

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
webmin

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-29: 1Technical Details · 2026-06-29: 106-29
Signal classification1 categories
Disclosure
1100.0%
Referenced assets2 URLs
By indicator
Full discourse1 post
  • Israel@f1tym1
    Disclosure

    Update: http://Cybersecuritynews.com reports two additional critical vulnerabilities not previously detailed in coverage of the Webmin patch cycle: CVE-2025-67738 (command execution via the Squid module) and CVE-2025-61541 (host header injection in password r… https://ift.tt/Ijd0mDX

    Post summary

    The update announces two additional critical Webmin vulnerabilities—CVE-2025-67738 (command execution through the Squid module) and CVE-2025-61541 (host header injection in password handling)—without providing PoCs, exploit details, or patches.

    0000065
    1.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwebminwebmin2.510--

Explore more