CVE-2025-61541: Webmin
High severity, CVSS 7.1. EPSS: 0.5% chance of exploitation in the next 30 days.
Webmin 2.510 is vulnerable to a Host Header Injection in the password reset functionality (forgot_send.cgi). The reset link sent to users is constructed using the HTTP Host header via get_webmin_email_url(). An attacker can manipulate the Host header to inject a malicious domain into the reset email. If a victim follows the poisoned link, the attacker can intercept the reset token and gain full control of the target account.
Affected products
- Webmin Webmin: version 2.510 only
Published 2025-10-16. Last modified 2026-06-17.