PT-2023-4161 · Webmin+1 · Webmin+1

CVE-2023-38304

·

Published

2023-07-31

·

Updated

2024-09-18

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Webmin version 2.021
Description The issue is related to a Stored Cross-Site Scripting (XSS) vulnerability in the Users and Groups functionality of Webmin. This vulnerability allows an attacker to store a malicious payload in the Group Name field when creating a new group, potentially leading to a remote attacker conducting an XSS attack.
Recommendations For Webmin version 2.021, consider disabling the Users and Groups functionality until a patch is available to prevent exploitation of the Stored Cross-Site Scripting vulnerability. Restrict access to the Group Name field to minimize the risk of storing malicious payloads.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-04473
CVE-2023-38304

Affected Products

Red Os
Webmin