CVE-2023-38305: XSS
Published Jul 31, 2023
·Updated
An issue was discovered in Webmin 2.021. The download functionality allows an attacker to exploit a Cross-Site Scripting (XSS) vulnerability. By providing a crafted download path containing a malicious payload, an attacker can inject arbitrary code, which is then executed within the context of the victim's browser when the download link is accessed.
Affected Software
1 affected component
webmin webmin=2.021
Event History
Jul 31, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-38305?
The severity of CVE-2023-38305 is medium (6.1).
2
What is the affected software for CVE-2023-38305?
The affected software for CVE-2023-38305 is Webmin 2.021.
3
What vulnerability does CVE-2023-38305 have?
CVE-2023-38305 has a Cross-Site Scripting (XSS) vulnerability.
4
How can an attacker exploit CVE-2023-38305?
An attacker can exploit CVE-2023-38305 by providing a crafted download path containing a malicious payload.
5
What is the fix for CVE-2023-38305?
A fix for CVE-2023-38305 is not specified in the provided information. Please refer to the references for more information.