CVE-2018-19191: XSS
Published Mar 17, 2019
·Updated
Webmin 1.890 has XSS via /config.cgi?webmin, the /shell/index.cgi history parameter, /shell/index.cgi?stripped=1, or the /webminlog/search.cgi uall or mall parameter.
Affected Software
1 affected component
webmin webmin=1.890
Event History
Mar 17, 2019
CVE Published
via MITRE·09:27 PM
Data Sourced
via MITRE·09:27 PM
Description
Frequently Asked Questions
1
What is CVE-2018-19191?
CVE-2018-19191 refers to a vulnerability in Webmin 1.890 that allows for cross-site scripting.
2
How severe is CVE-2018-19191?
CVE-2018-19191 has a severity rating of medium with a CVSS score of 5.4.
3
What is the affected software version for CVE-2018-19191?
The affected software version for CVE-2018-19191 is Webmin 1.890.
4
What is the CWE category for CVE-2018-19191?
CVE-2018-19191 falls under CWE category 79, which is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
5
How can I fix CVE-2018-19191?
To fix CVE-2018-19191, it is recommended to update Webmin to a version that has addressed the vulnerability.