Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-38305

Опубликовано: 31 июл. 2023
Источник: debian
EPSS Низкий

Описание

An issue was discovered in Webmin 2.021. The download functionality allows an attacker to exploit a Cross-Site Scripting (XSS) vulnerability. By providing a crafted download path containing a malicious payload, an attacker can inject arbitrary code, which is then executed within the context of the victim's browser when the download link is accessed.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
webminremovedpackage

EPSS

Процентиль: 54%
0.00311
Низкий

Связанные уязвимости

CVSS3: 6.1
nvd
почти 2 года назад

An issue was discovered in Webmin 2.021. The download functionality allows an attacker to exploit a Cross-Site Scripting (XSS) vulnerability. By providing a crafted download path containing a malicious payload, an attacker can inject arbitrary code, which is then executed within the context of the victim's browser when the download link is accessed.

CVSS3: 6.1
github
почти 2 года назад

An issue was discovered in Webmin 2.021. The download functionality allows an attacker to exploit a Cross-Site Scripting (XSS) vulnerability. By providing a crafted download path containing a malicious payload, an attacker can inject arbitrary code, which is then executed within the context of the victim's browser when the download link is accessed.

CVSS3: 6.1
fstec
почти 2 года назад

Уязвимость панели управления хостингом Webmin, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)

CVSS3: 8.8
redos
9 месяцев назад

Множественные уязвимости webmin

EPSS

Процентиль: 54%
0.00311
Низкий