First published: Fri Sep 15 2023(Updated: )
A reflected cross-site scripting (XSS) vulnerability in the File Manager function of Webmin v2.100 allows attackers to execute malicious scripts via injecting a crafted payload into the Replace in Results file.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webmin Webmin | =2.100 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-40984 is a reflected cross-site scripting (XSS) vulnerability in the File Manager function of Webmin v2.100.
CVE-2023-40984 allows attackers to execute malicious scripts by injecting a crafted payload into the Replace in Results file in Webmin v2.100.
CVE-2023-40984 has a severity rating of medium (5.4).
To fix CVE-2023-40984 in Webmin v2.100, it is recommended to update to a patched version of Webmin.
More information about CVE-2023-40984 can be found on the Webmin website and the GitHub repository for Webmin v2.100.