CVE-2023-38311: XSS
An issue was discovered in Webmin 2.021. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the System Logs Viewer functionality. The vulnerability allows an attacker to store a malicious payload in the configuration field, triggering the execution of the payload when saving the configuration or when accessing the System Logs Viewer page.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-38311?
CVE-2023-38311 is a Stored Cross-Site Scripting (XSS) vulnerability discovered in Webmin 2.021.
What is the severity of CVE-2023-38311?
The severity of CVE-2023-38311 is medium with a CVSS score of 5.4.
How does CVE-2023-38311 affect Webmin?
CVE-2023-38311 affects Webmin 2.021, allowing an attacker to store and execute malicious payloads in the System Logs Viewer functionality.
How can I fix CVE-2023-38311?
To fix CVE-2023-38311, it is recommended to update to a patched version of Webmin or apply the necessary security patches provided by the vendor.
What is the CWE classification of CVE-2023-38311?
CVE-2023-38311 is classified under CWE-79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').