PT-2023-30305 · Unknown · Virtualmin
Pavanughade43
·
Publicado
2023-10-31
·
Atualizado
2023-11-06
·
CVE-2023-47097
CVSS v3.1
5.4
Média
| Vetor | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Virtualmin version 7.7
Description
A Stored Cross-Site Scripting (XSS) issue in the Server Template under System Setting in Virtualmin allows remote attackers to inject arbitrary web script or HTML via the
Template name field while creating server templates. The Server Templates feature under System Settings is affected.Recommendations
For Virtualmin version 7.7, consider disabling the Server Templates feature under System Settings until a patch is available to prevent exploitation of the XSS issue. Restrict access to the Template name field to minimize the risk of arbitrary web script or HTML injection.
Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Virtualmin