PT-2024-4729 · Webmin+1 · Webmin+1
Toshitsugu Yoneyama
·
Published
2024-07-10
·
Updated
2025-10-08
·
CVE-2024-36451
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Webmin versions prior to 2.003
Description:
The issue is related to improper handling of insufficient permissions or privileges in the ajaxterm module of Webmin. This could allow an unauthorized user to hijack a console session, potentially leading to data referral, webpage alteration, or permanent server halt. The vulnerability may enable an attacker to escalate privileges.
Recommendations:
For versions prior to 2.003, update to version 2.003 or later to resolve the issue. As a temporary workaround, consider restricting access to the ajaxterm module to minimize the risk of exploitation. Additionally, review and ensure proper configuration of permissions and privileges within Webmin to prevent unauthorized access.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Os
Webmin