First published: Mon Jul 31 2023(Updated: )
An issue was discovered in Webmin 2.021. A Cross-site Scripting (XSS) Bypass vulnerability was discovered in the file upload functionality. Normally, the application restricts the upload of certain file types such as .svg, .php, etc., and displays an error message if a prohibited file type is detected. However, by following certain steps, an attacker can bypass these restrictions and inject malicious code.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webmin Webmin | =2.021 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-38306 is a Cross-site Scripting (XSS) Bypass vulnerability discovered in Webmin 2.021.
CVE-2023-38306 has a severity rating of 6.1 (Medium).
CVE-2023-38306 allows an attacker to bypass Cross-Site Scripting (XSS) protections in the file upload functionality of Webmin 2.021, potentially allowing them to execute malicious scripts in the victim's browser.
Currently, there is no known fix or patch available for CVE-2023-38306. It is recommended to disable or restrict access to the file upload functionality in Webmin 2.021 as a temporary mitigation.
You can find more information about CVE-2023-38306 in the Webmin Changelog and the GitHub repository where it was discovered.