PT-2017-14138 · Jamie Cameron · Webmin
Published
2017-10-19
·
Updated
2017-11-08
·
CVE-2017-15646
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Webmin versions prior to 1.860
Description
The issue allows for XSS with resultant remote code execution. It is exploited through the 'Download from remote URL' option under the 'Others/File Manager' menu, where an attacker can set up a malicious server to send an XSS payload upon receiving a file download request. This payload can lead to remote code execution, as demonstrated by an OS command in the value attribute of a
name='cmd' input element.Recommendations
For versions prior to 1.860, update to version 1.860 or later to resolve the issue. As a temporary workaround, consider restricting access to the 'Download from remote URL' option under the 'Others/File Manager' menu to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Webmin