Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p32v-wxmw-472h

Опубликовано: 31 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

An issue was discovered in Webmin 2.021. The download functionality allows an attacker to exploit a Cross-Site Scripting (XSS) vulnerability. By providing a crafted download path containing a malicious payload, an attacker can inject arbitrary code, which is then executed within the context of the victim's browser when the download link is accessed.

An issue was discovered in Webmin 2.021. The download functionality allows an attacker to exploit a Cross-Site Scripting (XSS) vulnerability. By providing a crafted download path containing a malicious payload, an attacker can inject arbitrary code, which is then executed within the context of the victim's browser when the download link is accessed.

EPSS

Процентиль: 60%
0.00406
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
около 2 лет назад

An issue was discovered in Webmin 2.021. The download functionality allows an attacker to exploit a Cross-Site Scripting (XSS) vulnerability. By providing a crafted download path containing a malicious payload, an attacker can inject arbitrary code, which is then executed within the context of the victim's browser when the download link is accessed.

CVSS3: 6.1
debian
около 2 лет назад

An issue was discovered in Webmin 2.021. The download functionality al ...

CVSS3: 6.1
fstec
около 2 лет назад

Уязвимость панели управления хостингом Webmin, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)

CVSS3: 8.8
redos
12 месяцев назад

Множественные уязвимости webmin

EPSS

Процентиль: 60%
0.00406
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79