Cross-Site Scripting Vulnerability in Webmin File Manager
CVE-2023-40985

5.4MEDIUM

Key Information:

Vendor

Webmin

Status
Vendor
CVE Published:
15 September 2023

What is CVE-2023-40985?

Webmin version 2.100 contains a vulnerability within its File Manager feature that allows attackers to exploit a Cross-Site Scripting (XSS) flaw. By injecting a malicious payload, an attacker can execute arbitrary scripts in the context of a user's web browser during file operations. This vulnerability poses a significant risk, as it can lead to unauthorized access to sensitive information and malicious actions performed on behalf of the user. Users of Webmin should review their configurations and apply relevant security measures to mitigate this threat.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.