PT-2023-4162 · Webmin+1 · Webmin+1

Publicado

2023-07-31

·

Atualizado

2024-09-19

·

CVE-2023-38303

CVSS v2.0

5.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Webmin version 2.021
Description The issue is related to the lack of protection of the web page structure in the Webmin control panel, allowing a remote attacker to conduct a cross-site scripting (XSS) attack. This can be exploited to achieve Remote Command Execution (RCE) through the real name parameter in the Users and Group section.
Recommendations For Webmin version 2.021, consider disabling the Users and Group's real name parameter until a patch is available to prevent Remote Command Execution (RCE) through stored Cross-Site Scripting (XSS) attacks.

Exploit

Correção

RCE

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-04474
CVE-2023-38303

Produtos afetados

Red Os
Webmin