CVE-2025-61541
⚠️ highSummary
Webmin 2.510 is vulnerable to a Host Header Injection in the password reset functionality (forgot_send.cgi). The reset link sent to users is constructed using the HTTP Host header via get_webmin_email_url(). An attacker can manipulate the Host header to inject a malicious domain into the reset email. If a victim follows the poisoned link, the attacker can intercept the reset token and gain full control of the target account.
CVSS Score
7.1
High
EPSS Score
0.1
Exploit Probability
Published Date
2025-10-16
First Seen: 2026-01-05
📊 Relative Risk Intelligence
This CVE is Moderate Risk - more severe than 53.3% of all 330,193 vulnerabilities in our database.
#154,204
Above average severity
Severity Percentile
🎯 CISA SSVC Assessment Updated: Oct 16, 2025
🔍 Exploitation Status
None
No known exploits
⚙️ Automatable
NO
Requires human interaction
💥 Technical Impact
Total
Complete system compromise possible
SSVC data provided by
CISA
Last Modified
2025-11-06
Source
NVD 🔗
CVSS Vector 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
CWE IDs (Weakness Types)