CVE-2023-43309: XSS
Published Sep 21, 2023
·Updated
There is a stored cross-site scripting (XSS) vulnerability in Webmin 2.002 and below via the Cluster Cron Job tab Input field, which allows attackers to run malicious scripts by injecting a specially crafted payload.
Affected Software
1 affected component
webmin webmin<=2.002
Event History
Sep 21, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this Webmin vulnerability?
The vulnerability ID of this Webmin vulnerability is CVE-2023-43309.
2
What is the title of this Webmin vulnerability?
The title of this Webmin vulnerability is 'There is a stored cross-site scripting (XSS) vulnerability in Webmin 2.002 and below via the Cluster Cron Job tab Input field.'
3
What is the severity of CVE-2023-43309?
The severity of CVE-2023-43309 is medium with a CVSS score of 4.8.
4
How does this vulnerability affect Webmin?
This vulnerability affects Webmin versions 2.002 and below.
5
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by injecting a specially crafted payload into the Cluster Cron Job tab Input field, allowing them to run malicious scripts.