CVE-2017-17089: XSS
custom/run.cgi in Webmin before 1.870 allows remote authenticated administrators to conduct XSS attacks via the description field in the custom command functionality.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2017-17089?
CVE-2017-17089 is a vulnerability in Webmin before 1.870 that allows remote authenticated administrators to conduct XSS attacks.
How does CVE-2017-17089 affect Webmin?
CVE-2017-17089 affects Webmin versions up to and including 1.860.
What is the severity of CVE-2017-17089?
CVE-2017-17089 has a severity rating of medium (4.8 out of 10).
How can remote authenticated administrators exploit CVE-2017-17089?
Remote authenticated administrators can exploit CVE-2017-17089 by injecting malicious scripts through the description field in the custom command functionality.
Are there any references for CVE-2017-17089?
Yes, you can find references for CVE-2017-17089 at the following links: [SecurityFocus](http://www.securityfocus.com/bid/102339) and [GitHub](https://github.com/webmin/webmin/commit/a9c97eea6c268fb83d93a817d58bac75e0d2599e).