Webmin 1.910 with user password changing enabled, vulnerable to CVE-2019-15107 (the backdoored release): the old parameter of password_change.cgi reaches a shell command, so a request with a | in it runs commands as root without logging in.
Pas commencéDockercommit 83732e8x86_64 · aarch64Secret
Exploit CVE-2019-15107 to run commands on the Webmin server as root and read /ctf/flag.
Le brief de ce lab se trouve dans son dépôt.