CVE-2014-3885: XSS
Published Jul 20, 2014
·Updated
Cross-site scripting (XSS) vulnerability in Webmin before 1.690 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. NOTE: this might overlap CVE-2014-3924.
Affected Software
9 affected components
webmin webmin<=1.680
webmin webmin=1.600
webmin webmin=1.610
webmin webmin=1.620
webmin webmin=1.630
webmin webmin=1.640
webmin webmin=1.650
webmin webmin=1.660
webmin webmin=1.670
Event History
Jul 20, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-3885?
CVE-2014-3885 is classified as a moderate severity vulnerability due to its potential to allow cross-site scripting by remote authenticated users.
2
How do I fix CVE-2014-3885?
To fix CVE-2014-3885, upgrade Webmin to version 1.690 or later, which addresses the vulnerability.
3
Who is affected by CVE-2014-3885?
CVE-2014-3885 affects all versions of Webmin prior to 1.690.
4
What type of vulnerability is CVE-2014-3885?
CVE-2014-3885 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2014-3885 be exploited by unauthenticated users?
No, CVE-2014-3885 requires an attacker to be an authenticated user to exploit the vulnerability.