Hijacking Console Sessions and Altering Webpages with Ajaxterm Vulnerability
CVE-2024-36451

Currently unrated

Key Information:

Vendor

Webmin

Status
Vendor
CVE Published:
10 July 2024

What is CVE-2024-36451?

Improper handling of insufficient permissions or privileges vulnerability exists in ajaxterm module of Webmin prior to 2.003. If this vulnerability is exploited, a console session may be hijacked by an unauthorized user. As a result, data within a system may be referred, a webpage may be altered, or a server may be permanently halted.

Affected Version(s)

Webmin prior to 2.003

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.