QID 731090

Date Published: 2024-01-23

QID 731090: Webmin Stored Cross-Site Scripting (XSS) Vulnerability (CVE-2023-43309)

Webmin is a powerful and flexible web-based server management control panel for Unix-like systems.

There is a stored cross-site scripting (XSS) vulnerability in Webmin 2.002 and below via the Cluster Cron Job tab Input field, which allows attackers to run malicious scripts by injecting a specially crafted payload.

Affected versions:
Webmin versions Upto 2.002

QID Detection Logic (Unauthenticated) :
This QID sends a HTTP GET request to the target application and determines vulnerable version of Webmin running based on the HTTP server header.

Successful exploitation of this vulnerability could allow attackers to run malicious scripts by injecting a specially crafted payload.

  • CVSS V3 rated as Medium - 4.8 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution
    Customers are advised to upgrade to latest version of Webmin to remediate this vulnerability.

    CVEs related to QID 731090

    Software Advisories
    Advisory ID Software Component Link
    Webmin Downloads URL Logo www.webmin.com/download.html