Reflected Cross-Site Scripting Vulnerability in Webmin by Virtualmin
CVE-2023-40983

6.1MEDIUM

Key Information:

Vendor

Webmin

Status
Vendor
CVE Published:
15 September 2023

What is CVE-2023-40983?

A reflected cross-site scripting (XSS) vulnerability in the File Manager function of Webmin v2.100 allows attackers to execute arbitrary scripts. This could be done by injecting a specially crafted payload into the Find in Results file, potentially leading to unauthorized access or data leakage. Users are advised to update their installations and mitigate potential risks by implementing security best practices.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-40983 : Reflected Cross-Site Scripting Vulnerability in Webmin by Virtualmin