Vulnerability record · CVE-2020-8821 · published 12 October 2020
CVE-2020-8821: Webmin Command Shell endpoint stored HTML injection in action logs
Webmin · Webmin
Webmin 1.941 and earlier does not properly validate input in the Command Shell endpoint's Command field. HTML entered there is stored and later rendered when the Action Logs menu displays logs, and the injected content persists across users. Because the rendered HTML is not executed as JavaScript, the practical risk is limited to content spoofing or defacement of the log view rather than script execution.
Description
An Improper Data Validation Vulnerability exists in Webmin 1.941 and earlier affecting the Command Shell Endpoint. A user may enter HTML code into the Command field and submit it. Then, after visiting the Action Logs Menu and displaying logs, the HTML code will be rendered (however, JavaScript is not executed). Changes are kept across users.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityThe flaw is an authenticated, interaction-dependent HTML injection with no script execution, so impact is limited despite a high EPSS score.
What it is
Webmin 1.941 and earlier does not properly validate input in the Command Shell endpoint's Command field. HTML entered there is stored and later rendered when the Action Logs menu displays logs, and the injected content persists across users. Because the rendered HTML is not executed as JavaScript, the practical risk is limited to content spoofing or defacement of the log view rather than script execution.
Impact
An authenticated attacker can plant arbitrary HTML that is displayed to other users viewing Action Logs, enabling misleading or spoofed log content. No script execution, session theft, or code execution is gained from this flaw as described.
Attack surface
Reached over the network through the Webmin web interface; the vector requires low privileges (an authenticated user) and user interaction from the victim who opens the Action Logs menu. No unauthenticated path is described.
Exploitation
Not listed in CISA KEV and no public exploit references are provided; EPSS is high (0.80215, 99.6th percentile), but that score reflects model output, not confirmed exploitation. The only references are vendor advisories.
What to do
- Upgrade Webmin to a version later than 1.941 per the vendor security page.
- Restrict Webmin access to trusted management networks and require strong authentication.
- Limit which accounts can use the Command Shell endpoint and review Action Logs permissions.
- Sanitize or escape HTML in the Command field and log rendering as a defense-in-depth measure.
Detection
- Review Action Logs for unexpected HTML tags or markup in command entries.
- Monitor Webmin audit logs for Command Shell submissions containing angle brackets or HTML entities.
- Alert on log-viewing activity by accounts that do not normally administer Webmin.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.webmin.com/security.html | Vendor Advisory |
| https://www.webmin.com/security.html | Vendor Advisory |
Track CVE-2020-8821 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-8821), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.