PT-2024-5735 · Webmin+1 · Webmin+1

Toshitsugu Yoneyama

·

Published

2024-07-09

·

Updated

2025-10-08

·

CVE-2024-36452

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Webmin versions prior to 2.003
Description A cross-site request forgery vulnerability exists in the ajaxterm module. If exploited, unintended operations may be performed when a user views a malicious page while logged in, potentially allowing data within a system to be referred, a webpage to be altered, or a server to be permanently halted.
Recommendations For versions prior to 2.003, update to version 2.003 or later to resolve the issue. As a temporary workaround, consider disabling the ajaxterm module until a patch is available. Restrict access to the ajaxterm module to minimize the risk of exploitation.

Fix

CSRF

Weakness Enumeration

Related Identifiers

BDU:2024-06448
CVE-2024-36452

Affected Products

Red Os
Webmin