PT-2024-4729 · Webmin+1 · Webmin+1

Toshitsugu Yoneyama

·

Published

2024-07-10

·

Updated

2025-10-08

·

CVE-2024-36451

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Webmin versions prior to 2.003
Description: The issue is related to improper handling of insufficient permissions or privileges in the ajaxterm module of Webmin. This could allow an unauthorized user to hijack a console session, potentially leading to data referral, webpage alteration, or permanent server halt. The vulnerability may enable an attacker to escalate privileges.
Recommendations: For versions prior to 2.003, update to version 2.003 or later to resolve the issue. As a temporary workaround, consider restricting access to the ajaxterm module to minimize the risk of exploitation. Additionally, review and ensure proper configuration of permissions and privileges within Webmin to prevent unauthorized access.

Fix

Weakness Enumeration

Related Identifiers

BDU:2024-05248
CVE-2024-36451

Affected Products

Red Os
Webmin