PT-2023-4162 · Webmin+1 · Webmin+1
Published
2023-07-31
·
Updated
2024-09-19
·
CVE-2023-38303
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Webmin version 2.021
Description
The issue is related to the lack of protection of the web page structure in the Webmin control panel, allowing a remote attacker to conduct a cross-site scripting (XSS) attack. This can be exploited to achieve Remote Command Execution (RCE) through the
real name parameter in the Users and Group section.Recommendations
For Webmin version 2.021, consider disabling the Users and Group's real name parameter until a patch is available to prevent Remote Command Execution (RCE) through stored Cross-Site Scripting (XSS) attacks.
Exploit
Fix
RCE
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Os
Webmin