CVE-2017-15644: Webmin

High severity, CVSS 8.6. EPSS: 8.9% chance of exploitation in the next 30 days.

SSRF exists in Webmin 1.850 via the PATH_INFO to tunnel/link.cgi, as demonstrated by a GET request for tunnel/link.cgi/http://INTRANET-IP:8000.

Affected products

  • Webmin Webmin: up to and including 1.850

Published 2017-10-19. Last modified 2026-06-17.