PT-2023-4162 · Webmin+1 · Webmin+1

Published

2023-07-31

·

Updated

2024-09-19

·

CVE-2023-38303

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Webmin version 2.021
Description The issue is related to the lack of protection of the web page structure in the Webmin control panel, allowing a remote attacker to conduct a cross-site scripting (XSS) attack. This can be exploited to achieve Remote Command Execution (RCE) through the real name parameter in the Users and Group section.
Recommendations For Webmin version 2.021, consider disabling the Users and Group's real name parameter until a patch is available to prevent Remote Command Execution (RCE) through stored Cross-Site Scripting (XSS) attacks.

Exploit

Fix

RCE

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-04474
CVE-2023-38303

Affected Products

Red Os
Webmin