PT-2020-20303 · Webmin · Webmin

Mauro Caseres

·

Published

2020-10-12

·

Updated

2020-11-08

·

CVE-2020-8820

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Webmin versions 1.941 and earlier
Description An issue exists where a user can enter any XSS payload into the Command field of the "Cluster Shell Commands" endpoint and execute it. Upon revisiting the Cluster Shell Commands Menu, the XSS payload will be rendered and executed.
Recommendations For Webmin versions 1.941 and earlier, consider disabling access to the Cluster Shell Commands endpoint until a fix is available. As a temporary workaround, restrict the ability to enter custom commands in the Command field to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-8820
MGASA-2020-0400

Affected Products

Webmin