Cross-site scripting vulnerability exists in session_login.cgi of Webmin versions prior to 1.970 and Usermin versions prior to 1.820. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product. As a result, a webpage may be altered or sensitive information such as a credential may be disclosed.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NWebmin Usermin
APPWebmin< 1.820Webmin
APPWebmin< 1.970
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
Related vulnerabilities
CVE-2019-15107CRITICAL9.8⚠ KEVPL ✓same product
Command Injection w Webmin <=1.920 — nieautoryzowane RCE
CVE-2015-2079CRITICAL9.9PL ✓same product
RCE w Usermin przez błędne wywołanie Perl open() w uconfig_save.cgi
CVE-2022-36446CRITICAL9.8PL ✓same product
Webmin – brak HTML escaping umożliwia RCE przez command injection
CVE-2021-32157CRITICAL9.6PL ✓same product
XSS w Webmin 1.973 — funkcja Scheduled Cron Jobs
CVE-2021-31761CRITICAL9.6PL ✓same product
Webmin 1.973 — reflected XSS prowadzący do Remote Command Execution