First published: Thu Mar 21 2019(Updated: )
Webmin 1.890 has XSS via /config.cgi?webmin, the /shell/index.cgi history parameter, /shell/index.cgi?stripped=1, or the /webminlog/search.cgi uall or mall parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webmin Webmin | =1.890 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19191 refers to a vulnerability in Webmin 1.890 that allows for cross-site scripting.
CVE-2018-19191 has a severity rating of medium with a CVSS score of 5.4.
The affected software version for CVE-2018-19191 is Webmin 1.890.
CVE-2018-19191 falls under CWE category 79, which is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
To fix CVE-2018-19191, it is recommended to update Webmin to a version that has addressed the vulnerability.