Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wqmw-cmc2-6cf5

Опубликовано: 31 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

An issue was discovered in Webmin 2.021. A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the package search functionality. The vulnerability allows an attacker to inject a malicious payload in the "Search for Package" field, which gets reflected back in the application's response, leading to the execution of arbitrary JavaScript code within the context of the victim's browser.

An issue was discovered in Webmin 2.021. A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the package search functionality. The vulnerability allows an attacker to inject a malicious payload in the "Search for Package" field, which gets reflected back in the application's response, leading to the execution of arbitrary JavaScript code within the context of the victim's browser.

EPSS

Процентиль: 66%
0.00528
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
около 2 лет назад

An issue was discovered in Webmin 2.021. A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the package search functionality. The vulnerability allows an attacker to inject a malicious payload in the "Search for Package" field, which gets reflected back in the application's response, leading to the execution of arbitrary JavaScript code within the context of the victim's browser.

CVSS3: 6.1
debian
около 2 лет назад

An issue was discovered in Webmin 2.021. A Reflected Cross-Site Script ...

CVSS3: 5.4
fstec
около 2 лет назад

Уязвимость панели управления хостингом Webmin, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)

CVSS3: 8.8
redos
12 месяцев назад

Множественные уязвимости webmin

EPSS

Процентиль: 66%
0.00528
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79