Webmin 1.910 with user password changing enabled, vulnerable to CVE-2019-15107 (the backdoored release): the old parameter of password_change.cgi reaches a shell command, so a request with a | in it runs commands as root without logging in.
Not startedDockercommit a614b26x86_64 · aarch64Secret
Exploit CVE-2019-15107 to run commands on the Webmin server and get a root shell.
The brief for this lab lives in its repository.