PT-2023-4162 · Webmin+1 · Webmin+1
Publicado
2023-07-31
·
Atualizado
2024-09-19
·
CVE-2023-38303
CVSS v2.0
5.5
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Webmin version 2.021
Description
The issue is related to the lack of protection of the web page structure in the Webmin control panel, allowing a remote attacker to conduct a cross-site scripting (XSS) attack. This can be exploited to achieve Remote Command Execution (RCE) through the
real name parameter in the Users and Group section.Recommendations
For Webmin version 2.021, consider disabling the Users and Group's real name parameter until a patch is available to prevent Remote Command Execution (RCE) through stored Cross-Site Scripting (XSS) attacks.
Exploit
Correção
RCE
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Red Os
Webmin