First published: Mon Jul 31 2023(Updated: )
An issue was discovered in Webmin 2.021. The download functionality allows an attacker to exploit a Cross-Site Scripting (XSS) vulnerability. By providing a crafted download path containing a malicious payload, an attacker can inject arbitrary code, which is then executed within the context of the victim's browser when the download link is accessed.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webmin Webmin | =2.021 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-38305 is medium (6.1).
The affected software for CVE-2023-38305 is Webmin 2.021.
CVE-2023-38305 has a Cross-Site Scripting (XSS) vulnerability.
An attacker can exploit CVE-2023-38305 by providing a crafted download path containing a malicious payload.
A fix for CVE-2023-38305 is not specified in the provided information. Please refer to the references for more information.