QID 731091

Date Published: 2024-01-23

QID 731091: Webmin Multiple Cross-Site Scripting (XSS) Vulnerabilities

Webmin is a powerful and flexible web-based server management control panel for Unix-like systems.

In affected versions of Webmin, multiple Cross-Site Scripting (XSS) Vulnerabilities are found in version 2.000

Affected versions:
Webmin version 2.000

QID Detection Logic (Unauthenticated) :
This QID sends a HTTP GET request to the target application and determines vulnerable version of Webmin running based on the HTTP server header.

Successful exploitation of this vulnerability may allow attacker to execute arbitrary JavaScript code and capture cookies of the users using affected module.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to upgrade to latest version of Webmin to remediate this vulnerability.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    Webmin Downloads URL Logo www.webmin.com/download.html