PT-2023-30305 · Unknown · Virtualmin
Pavanughade43
·
Published
2023-10-31
·
Updated
2023-11-06
·
CVE-2023-47097
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Virtualmin version 7.7
Description
A Stored Cross-Site Scripting (XSS) issue in the Server Template under System Setting in Virtualmin allows remote attackers to inject arbitrary web script or HTML via the
Template name field while creating server templates. The Server Templates feature under System Settings is affected.Recommendations
For Virtualmin version 7.7, consider disabling the Server Templates feature under System Settings until a patch is available to prevent exploitation of the XSS issue. Restrict access to the Template name field to minimize the risk of arbitrary web script or HTML injection.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Virtualmin