CVE-2023-38306: XSS
An issue was discovered in Webmin 2.021. A Cross-site Scripting (XSS) Bypass vulnerability was discovered in the file upload functionality. Normally, the application restricts the upload of certain file types such as .svg, .php, etc., and displays an error message if a prohibited file type is detected. However, by following certain steps, an attacker can bypass these restrictions and inject malicious code.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-38306?
CVE-2023-38306 is a Cross-site Scripting (XSS) Bypass vulnerability discovered in Webmin 2.021.
What is the severity of CVE-2023-38306?
CVE-2023-38306 has a severity rating of 6.1 (Medium).
How does CVE-2023-38306 work?
CVE-2023-38306 allows an attacker to bypass Cross-Site Scripting (XSS) protections in the file upload functionality of Webmin 2.021, potentially allowing them to execute malicious scripts in the victim's browser.
How can I fix CVE-2023-38306?
Currently, there is no known fix or patch available for CVE-2023-38306. It is recommended to disable or restrict access to the file upload functionality in Webmin 2.021 as a temporary mitigation.
Is there any additional information about CVE-2023-38306?
You can find more information about CVE-2023-38306 in the Webmin Changelog and the GitHub repository where it was discovered.