HIGH🇵🇱 Wersja polska

CVE-2024-36451

CVSS 8.8v3.1pub. 2024-07-10upd. 2025-10-08

Improper handling of insufficient permissions or privileges vulnerability exists in ajaxterm module of Webmin prior to 2.003. If this vulnerability is exploited, a console session may be hijacked by an unauthorized user. As a result, data within a system may be referred, a webpage may be altered, or a server may be permanently halted.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Webmin

    APP
    Webmin
    < 2.003
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2019-15107CRITICAL9.8⚠ KEVPL ✓same product

Command Injection w Webmin <=1.920 — nieautoryzowane RCE

CVE-2022-36446CRITICAL9.8PL ✓same product

Webmin – brak HTML escaping umożliwia RCE przez command injection

CVE-2021-32157CRITICAL9.6PL ✓same product

XSS w Webmin 1.973 — funkcja Scheduled Cron Jobs

CVE-2021-31761CRITICAL9.6PL ✓same product

Webmin 1.973 — reflected XSS prowadzący do Remote Command Execution

CVE-2020-35769CRITICAL9.8PL ✓same product

Webmin 1.962 (Windows): błędna obsługa znaków specjalnych w miniserv.pl