First published: Wed Oct 10 2018(Updated: )
Virtualmin 6.03 allows XSS via the query string, as demonstrated by the webmin_search.cgi URI.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Virtualmin | =6.03 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-18208 is a vulnerability in Virtualmin 6.03 that allows cross-site scripting (XSS) attacks through the query string.
CVE-2018-18208 affects Virtualmin 6.03 by allowing XSS attacks via the query string.
CVE-2018-18208 has a severity level of medium with a CVSS score of 6.1.
To fix CVE-2018-18208 in Virtualmin, you should update to a version that is not affected by the vulnerability if available.
You can find more information about CVE-2018-18208 at the following URL: https://0day.today/exploit/description/31282