CVE-2017-9313: XSS
Multiple Cross-site scripting (XSS) vulnerabilities in Webmin before 1.850 allow remote attackers to inject arbitrary web script or HTML via the sec parameter to viewman.cgi, the referers parameter to changereferers.cgi, or the name parameter to saveuser.cgi. NOTE: these issues were not fixed in 1.840.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9313?
CVE-2017-9313 is categorized as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2017-9313?
To fix CVE-2017-9313, upgrade Webmin to version 1.850 or later, as it contains patches for these vulnerabilities.
What are the potential impacts of CVE-2017-9313?
The potential impacts of CVE-2017-9313 include unauthorized code execution in the context of a user's session, leading to data theft or manipulation.
Which versions of Webmin are affected by CVE-2017-9313?
Webmin versions prior to 1.850, specifically up to 1.840, are affected by CVE-2017-9313.
Can CVE-2017-9313 be exploited remotely?
Yes, CVE-2017-9313 can be exploited remotely by attackers to inject arbitrary web scripts through specific parameters.