Cross-site scripting vulnerability exists in session_login.cgi of Webmin versions prior to 1.970 and Usermin versions prior to 1.820. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product. As a result, a webpage may be altered or sensitive information such as a credential may be disclosed.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NWebmin Usermin
APPWebmin< 1.820Webmin
APPWebmin< 1.970
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
XSS
CWE
Powiązane podatności
CVE-2019-15107CRITICAL9.8⚠ KEVPL ✓ten sam produkt
Command Injection w Webmin <=1.920 — nieautoryzowane RCE
CVE-2015-2079CRITICAL9.9PL ✓ten sam produkt
RCE w Usermin przez błędne wywołanie Perl open() w uconfig_save.cgi
CVE-2022-36446CRITICAL9.8PL ✓ten sam produkt
Webmin – brak HTML escaping umożliwia RCE przez command injection
CVE-2021-32157CRITICAL9.6PL ✓ten sam produkt
XSS w Webmin 1.973 — funkcja Scheduled Cron Jobs
CVE-2021-31761CRITICAL9.6PL ✓ten sam produkt
Webmin 1.973 — reflected XSS prowadzący do Remote Command Execution