xmlrpc.cgi in Webmin through 1.930 allows authenticated XXE attacks. By default, only root, admin, and sysadm can access xmlrpc.cgi.Referenceshttps://www.calypt.com/blog/index.php/authenticated-xxe-on-webmin/