← Vulnerability feed

Vulnerability record · CVE-2020-8821 · published 12 October 2020

CVE-2020-8821: Webmin Command Shell endpoint stored HTML injection in action logs

Webmin · Webmin

Webmin 1.941 and earlier does not properly validate input in the Command Shell endpoint's Command field. HTML entered there is stored and later rendered when the Action Logs menu displays logs, and the injected content persists across users. Because the rendered HTML is not executed as JavaScript, the practical risk is limited to content spoofing or defacement of the log view rather than script execution.

5.4 CVSS 3.1 Medium EPSS 80% · top 0.4% CWE-79 · Cross-site scripting
5.4CVSS 3.1 base score, v2 3.5
80%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An Improper Data Validation Vulnerability exists in Webmin 1.941 and earlier affecting the Command Shell Endpoint. A user may enter HTML code into the Command field and submit it. Then, after visiting the Action Logs Menu and displaying logs, the HTML code will be rendered (however, JavaScript is not executed). Changes are kept across users.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

medium priorityThe flaw is an authenticated, interaction-dependent HTML injection with no script execution, so impact is limited despite a high EPSS score.

What it is

Webmin 1.941 and earlier does not properly validate input in the Command Shell endpoint's Command field. HTML entered there is stored and later rendered when the Action Logs menu displays logs, and the injected content persists across users. Because the rendered HTML is not executed as JavaScript, the practical risk is limited to content spoofing or defacement of the log view rather than script execution.

Impact

An authenticated attacker can plant arbitrary HTML that is displayed to other users viewing Action Logs, enabling misleading or spoofed log content. No script execution, session theft, or code execution is gained from this flaw as described.

Attack surface

Reached over the network through the Webmin web interface; the vector requires low privileges (an authenticated user) and user interaction from the victim who opens the Action Logs menu. No unauthenticated path is described.

Exploitation

Not listed in CISA KEV and no public exploit references are provided; EPSS is high (0.80215, 99.6th percentile), but that score reflects model output, not confirmed exploitation. The only references are vendor advisories.

What to do

  • Upgrade Webmin to a version later than 1.941 per the vendor security page.
  • Restrict Webmin access to trusted management networks and require strong authentication.
  • Limit which accounts can use the Command Shell endpoint and review Action Logs permissions.
  • Sanitize or escape HTML in the Command field and log rendering as a defense-in-depth measure.

Detection

  • Review Action Logs for unexpected HTML tags or markup in command entries.
  • Monitor Webmin audit logs for Command Shell submissions containing angle brackets or HTML entities.
  • Alert on log-viewing activity by accounts that do not normally administer Webmin.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-8821 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-15107Webmin password_change.cgi command injectionWebmin through 1.920 passes the 'old' parameter in password_change.cgi into a shell command without sanitization, allowing OS command injection. The …KEVEPSS 100%analysed10.0CVE-2005-1177Usermin vulnerabilityUnknown vulnerability in (1) Webmin and (2) Usermin before 1.200 causes Webmin to change permissions and ownership of configuration files, with unkno…EPSS 1.8%10.0CVE-2003-0101Engardelinux guardian digital webtool vulnerabilityminiserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage returns (…EPSS 15%10.0CVE-2002-2201Webmin vulnerabilityThe Printer Administration module for Webmin 0.990 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the …EPSS 3.3%10.0CVE-2001-1196Webmin vulnerabilityDirectory traversal vulnerability in edit_action.cgi of Webmin Directory 0.91 allows attackers to gain privileges via a '..' (dot dot) in the argumen…EPSS 9.8%9.8CVE-2022-36446Webmin apt-lib.pl command injection via unescaped UI commandWebmin before 1.997 fails to HTML-escape a UI command in software/apt-lib.pl, allowing injection of commands through that interface. The flaw is remo…EPSS 96%analysed9.8CVE-2020-35769Webmin vulnerabilityminiserv.pl in Webmin 1.962 on Windows mishandles special characters in query arguments to the CGI program.EPSS 1.8%9.8CVE-2018-8712Webmin path traversal vulnerabilityAn issue was discovered in Webmin 1.840 and 1.880 when the default Yes setting of "Can view any file as a log file" is enabled. As a result of weak d…EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2020-8821), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.