← Voltar para CVEs
CVE-2023-38309
MEDIUM6.1
Descricao
An issue was discovered in Webmin 2.021. A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the package search functionality. The vulnerability allows an attacker to inject a malicious payload in the "Search for Package" field, which gets reflected back in the application's response, leading to the execution of arbitrary JavaScript code within the context of the victim's browser.
Detalhes CVE
Pontuacao CVSS v3.16.1
SeveridadeMEDIUM
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioREQUIRED
Publicado7/31/2023
Ultima modificacao11/21/2024
Fontenvd
Avistamentos honeypot0
Produtos afetados
webmin:webmin
Fraquezas (CWE)
CWE-79
Referencias
https://webmin.com/tags/webmin-changelog/(cve@mitre.org)
https://github.com/jaysharma786/Webmin-2.021/blob/main/CVE-2023-38309(af854a3a-2127-422b-91ae-364da2661108)
https://webmin.com/tags/webmin-changelog/(af854a3a-2127-422b-91ae-364da2661108)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.