First published: Thu Sep 21 2023(Updated: )
There is a stored cross-site scripting (XSS) vulnerability in Webmin 2.002 and below via the Cluster Cron Job tab Input field, which allows attackers to run malicious scripts by injecting a specially crafted payload.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webmin Webmin | <=2.002 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this Webmin vulnerability is CVE-2023-43309.
The title of this Webmin vulnerability is 'There is a stored cross-site scripting (XSS) vulnerability in Webmin 2.002 and below via the Cluster Cron Job tab Input field.'
The severity of CVE-2023-43309 is medium with a CVSS score of 4.8.
This vulnerability affects Webmin versions 2.002 and below.
An attacker can exploit this vulnerability by injecting a specially crafted payload into the Cluster Cron Job tab Input field, allowing them to run malicious scripts.