QID 730088
Date Published: 2021-05-19
QID 730088: Webmin Cross Site Scripting Vulnerability
Webmin is a web-based interface for system administration for Unix, although recent versions can also be installed and run on Windows.
A user with privileges to create custom commands could exploit other users via unescaped HTML.
Affected Versions:
Webmin less or equal to 1.941.
QID Detection Logic:
This QID sends specially crafted GET/POST request to check if the target is vulnerable or not.
Successful exploitation would allow an authenticated attacker to gain control over the target system.
Solution
For more information visit here.
Vendor References
- Webmin Security Advisory -
www.webmin.com/security.html
CVEs related to QID 730088
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Webmin |
|