CVE-2023-38309
- EPSS 0.53%
- Veröffentlicht 31.07.2023 15:15:10
- Zuletzt bearbeitet 21.11.2024 08:13:17
An issue was discovered in Webmin 2.021. A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the package search functionality. The vulnerability allows an attacker to inject a malicious payload in the "Search for Package" field, wh...
CVE-2023-38310
- EPSS 0.17%
- Veröffentlicht 31.07.2023 15:15:10
- Zuletzt bearbeitet 21.11.2024 08:13:17
An issue was discovered in Webmin 2.021. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the configuration settings of the system logs functionality. The vulnerability allows an attacker to store an XSS payload in the configuratio...
CVE-2023-38311
- EPSS 0.17%
- Veröffentlicht 31.07.2023 15:15:10
- Zuletzt bearbeitet 21.11.2024 08:13:18
An issue was discovered in Webmin 2.021. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the System Logs Viewer functionality. The vulnerability allows an attacker to store a malicious payload in the configuration field, triggerin...
CVE-2023-38308
- EPSS 0.53%
- Veröffentlicht 31.07.2023 15:15:10
- Zuletzt bearbeitet 21.11.2024 08:13:17
An issue was discovered in Webmin 2.021. A Cross-Site Scripting (XSS) vulnerability was discovered in the HTTP Tunnel functionality when handling third-party domain URLs. By providing a crafted URL from a third-party domain, an attacker can inject ma...
CVE-2022-3844
- EPSS 0.09%
- Veröffentlicht 02.11.2022 20:15:11
- Zuletzt bearbeitet 21.11.2024 07:20:21
A vulnerability, which was classified as problematic, was found in Webmin 2.001. Affected is an unknown function of the file xterm/index.cgi. The manipulation leads to basic cross site scripting. It is possible to launch the attack remotely. Upgradin...
CVE-2022-36880
- EPSS 0.62%
- Veröffentlicht 27.07.2022 04:15:10
- Zuletzt bearbeitet 21.11.2024 07:13:58
The Read Mail module in Webmin 1.995 and Usermin through 1.850 allows XSS via a crafted HTML e-mail message.
CVE-2022-36446
- EPSS 93.71%
- Veröffentlicht 25.07.2022 06:15:07
- Zuletzt bearbeitet 21.11.2024 07:13:01
software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.
CVE-2022-30708
- EPSS 4.69%
- Veröffentlicht 15.05.2022 03:15:07
- Zuletzt bearbeitet 21.11.2024 07:03:13
Webmin through 1.991, when the Authentic theme is used, allows remote code execution when a user has been manually created (i.e., not created in Virtualmin or Cloudmin). This occurs because settings-editor_write.cgi does not properly restrict the fil...
CVE-2021-32158
- EPSS 8.09%
- Veröffentlicht 11.04.2022 06:15:08
- Zuletzt bearbeitet 21.11.2024 06:06:53
A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Upload and Download feature.
CVE-2021-32156
- EPSS 8.02%
- Veröffentlicht 11.04.2022 06:15:08
- Zuletzt bearbeitet 21.11.2024 06:06:52
A cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.