QID 150666
Date Published: 2023-04-05
QID 150666: Webmin Cross-Site Scripting (XSS) Vulnerability (CVE-2022-36880)
Webmin is a powerful and flexible web-based server management control panel for Unix-like systems.
In affected versions of Webmin, a XSS vulnerability exits in the HTTP Tunnel module where if a less-privileged Webmin user is given permission to edit the configuration of the HTTP Tunnel module, he/she could captures cookies belonging to other Webmin users that use the module.
Affected versions:
Webmin versions prior to 1.995
QID Detection Logic (Unauthenticated) :
This QID sends a HTTP GET request to the target application and determines vulnerable version of Webmin running based on the HTTP server header.
Successful exploitation could allow an attacker to execute arbitrary JavaScript code in the context of the interface or allow the attacker to access sensitive, browser-based information.
- Webmin Security -
webmin.com/security/
CVEs related to QID 150666
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Webmin Security |
|