QID 731092

Date Published: 2024-01-23

QID 731092: Webmin Multiple Cross-Site Scripting (XSS) Vulnerabilities

Webmin is a powerful and flexible web-based server management control panel for Unix-like systems.

In affected versions of Webmin, multiple Cross-Site Scripting (XSS) Vulnerabilities are found in version 2.001

Affected versions:
Webmin version 2.001

QID Detection Logic (Unauthenticated) :
This QID sends a HTTP GET request to the target application and determines vulnerable version of Webmin running based on the HTTP server header.

Successful exploitation of this vulnerability may allow attacker to execute arbitrary JavaScript code and capture cookies of the users using affected module.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to upgrade to latest version of Webmin to remediate this vulnerability.
    Vendor References

    CVEs related to QID 731092

    Software Advisories
    Advisory ID Software Component Link
    Webmin Downloads URL Logo www.webmin.com/download.html