Reflected Cross-Site Scripting Vulnerability in Webmin by Virtualmin
CVE-2023-40984
5.4MEDIUM
What is CVE-2023-40984?
A reflected cross-site scripting (XSS) vulnerability exists in the File Manager function of Webmin v2.100. This security flaw allows attackers to execute malicious scripts by injecting crafted payloads through the Replace in Results file mechanism. Successful exploitation could lead to unauthorized actions on behalf of users, making it essential for administrators to apply security best practices and update their systems promptly.