First published: Sat Dec 30 2017(Updated: )
custom/run.cgi in Webmin before 1.870 allows remote authenticated administrators to conduct XSS attacks via the description field in the custom command functionality.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webmin Webmin | <=1.860 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-17089 is a vulnerability in Webmin before 1.870 that allows remote authenticated administrators to conduct XSS attacks.
CVE-2017-17089 affects Webmin versions up to and including 1.860.
CVE-2017-17089 has a severity rating of medium (4.8 out of 10).
Remote authenticated administrators can exploit CVE-2017-17089 by injecting malicious scripts through the description field in the custom command functionality.
Yes, you can find references for CVE-2017-17089 at the following links: [SecurityFocus](http://www.securityfocus.com/bid/102339) and [GitHub](https://github.com/webmin/webmin/commit/a9c97eea6c268fb83d93a817d58bac75e0d2599e).