PT-2017-14138 · Jamie Cameron · Webmin

Published

2017-10-19

·

Updated

2017-11-08

·

CVE-2017-15646

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Webmin versions prior to 1.860
Description The issue allows for XSS with resultant remote code execution. It is exploited through the 'Download from remote URL' option under the 'Others/File Manager' menu, where an attacker can set up a malicious server to send an XSS payload upon receiving a file download request. This payload can lead to remote code execution, as demonstrated by an OS command in the value attribute of a name='cmd' input element.
Recommendations For versions prior to 1.860, update to version 1.860 or later to resolve the issue. As a temporary workaround, consider restricting access to the 'Download from remote URL' option under the 'Others/File Manager' menu to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-15646

Affected Products

Webmin