QID 730088

Date Published: 2021-05-19

QID 730088: Webmin Cross Site Scripting Vulnerability

Webmin is a web-based interface for system administration for Unix, although recent versions can also be installed and run on Windows. A user with privileges to create custom commands could exploit other users via unescaped HTML.

Affected Versions:
Webmin less or equal to 1.941.

QID Detection Logic:
This QID sends specially crafted GET/POST request to check if the target is vulnerable or not.

Successful exploitation would allow an authenticated attacker to gain control over the target system.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    For more information visit here.
    Vendor References

    CVEs related to QID 730088

    Software Advisories
    Advisory ID Software Component Link
    Webmin URL Logo www.webmin.com/security.html