QID 730861

Date Published: 2023-08-01

QID 730861: Webmin Multiple Cross-Site Scripting (XSS) Vulnerabilities

Webmin is a powerful and flexible web-based server management control panel for Unix-like systems.

Affected versions:
Webmin version 2.021.

QID Detection Logic (Unauthenticated) :
This QID sends a HTTP GET request to the target application and determines vulnerable version of Webmin running based on the HTTP server header.

Successful exploitation of this vulnerability may allow remote code execution

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution
    Vendor has released patched information visit Webmin Security Advisory.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    Webmin advisory URL Logo webmin.com/changelog/webmin-2.100-released/