First published: Mon Jul 31 2023(Updated: )
An issue was discovered in Webmin 2.021. A Cross-Site Scripting (XSS) vulnerability was discovered in the HTTP Tunnel functionality when handling third-party domain URLs. By providing a crafted URL from a third-party domain, an attacker can inject malicious code. leading to the execution of arbitrary JavaScript code within the context of the victim's browser.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webmin Webmin | =2.021 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-38308 is a Cross-Site Scripting (XSS) vulnerability discovered in Webmin 2.021.
CVE-2023-38308 affects Webmin version 2.021.
The severity of CVE-2023-38308 is medium with a CVSS score of 6.1.
An attacker can exploit CVE-2023-38308 by providing a crafted URL from a third-party domain to inject malicious code.
Yes, you can refer to the following links: [1] https://github.com/jaysharma786/Webmin-2.021/blob/main/CVE-2023-38308 , [2] https://webmin.com/tags/webmin-changelog/