CVE-2023-40985: XSS
Published Sep 15, 2023
·Updated
An issue was discovered in Webmin 2.100. The File Manager functionality allows an attacker to exploit a Cross-Site Scripting (XSS) vulnerability. By providing a malicious payload, an attacker can inject arbitrary code, which is then executed within the context of the victim's browser when any file is searched/replaced.
Affected Software
1 affected component
webmin webmin=2.100
Event History
Sep 15, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-40985.
2
What is the severity level of CVE-2023-40985?
CVE-2023-40985 has a severity level of medium (5.4).
3
What is the affected version of Webmin?
The affected version of Webmin is 2.100.
4
What is the CWE ID associated with CVE-2023-40985?
The CWE ID associated with CVE-2023-40985 is 79.
5
How can an attacker exploit CVE-2023-40985?
An attacker can exploit CVE-2023-40985 by using the File Manager functionality in Webmin to inject arbitrary code and execute it within the context of a victim's browser.