First published: Mon Oct 12 2020(Updated: )
An Improper Data Validation Vulnerability exists in Webmin 1.941 and earlier affecting the Command Shell Endpoint. A user may enter HTML code into the Command field and submit it. Then, after visiting the Action Logs Menu and displaying logs, the HTML code will be rendered (however, JavaScript is not executed). Changes are kept across users.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webmin Webmin | <=1.941 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-8821 is an Improper Data Validation Vulnerability in Webmin 1.941 and earlier affecting the Command Shell Endpoint.
CVE-2020-8821 allows a user to enter HTML code into the Command field and have it rendered in the Action Logs Menu.
The severity of CVE-2020-8821 is medium with a severity score of 5.4.
To fix CVE-2020-8821 in Webmin, update to version 1.942 or later.
For more information about CVE-2020-8821, you can visit the Webmin security advisory page at https://www.webmin.com/security.html.