QID 731090
Date Published: 2024-01-23
QID 731090: Webmin Stored Cross-Site Scripting (XSS) Vulnerability (CVE-2023-43309)
Webmin is a powerful and flexible web-based server management control panel for Unix-like systems.
There is a stored cross-site scripting (XSS) vulnerability in Webmin 2.002 and below via the Cluster Cron Job tab Input field, which allows attackers to run malicious scripts by injecting a specially crafted payload.
Affected versions:
Webmin versions Upto 2.002
QID Detection Logic (Unauthenticated) :
This QID sends a HTTP GET request to the target application and determines vulnerable version of Webmin running based on the HTTP server header.
Successful exploitation of this vulnerability could allow attackers to run malicious scripts by injecting a specially crafted payload.
Solution
Customers are advised to upgrade to latest version of Webmin to remediate this vulnerability.
Vendor References
CVEs related to QID 731090
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Webmin Downloads |
|