HTB · Easy
Postman — Unauthenticated Redis to Webmin RCE
An unauthenticated Redis instance allows SSH key injection for initial access. A backup encrypted private key cracks to reveal credentials for user Matt, then Webmin 1.910 RCE (CVE-2019-12840) delivers a root shell.