CVE-2014-3886: XSS
Published Jul 20, 2014
·Updated
Cross-site scripting (XSS) vulnerability in Webmin before 1.690, when referrer checking is disabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this might overlap CVE-2014-3924.
Affected Software
9 affected components
webmin webmin<=1.680
webmin webmin=1.600
webmin webmin=1.610
webmin webmin=1.620
webmin webmin=1.630
webmin webmin=1.640
webmin webmin=1.650
webmin webmin=1.660
webmin webmin=1.670
Event History
Jul 20, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-3886?
CVE-2014-3886 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2014-3886?
To fix CVE-2014-3886, you should upgrade Webmin to version 1.690 or later.
3
What types of attacks can be executed due to CVE-2014-3886?
CVE-2014-3886 allows attackers to inject arbitrary web scripts or HTML into the Webmin interface.
4
In which versions of Webmin is CVE-2014-3886 present?
CVE-2014-3886 affects Webmin versions 1.680 and earlier.
5
What condition allows CVE-2014-3886 to be exploited?
CVE-2014-3886 can be exploited when referrer checking is disabled in Webmin.