An issue was discovered in Webmin 2.021. A Cross-Site Scripting (XSS) vulnerability was discovered in the HTTP Tunnel functionality when handling third-party domain URLs. By providing a crafted URL from a third-party domain, an attacker can inject malicious code. leading to the execution of arbitrary JavaScript code within the context of the victim's browser.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-42127 An issue was discovered in Webmin 2.021. A Cross-Site Scripting (XSS) vulnerability was discovered in the HTTP Tunnel functionality when handling third-party domain URLs. By providing a crafted URL from a third-party domain, an attacker can inject malicious code. leading to the execution of arbitrary JavaScript code within the context of the victim's browser.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 22 Oct 2024 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-10-22T17:50:05.120Z

Reserved: 2023-07-14T00:00:00

Link: CVE-2023-38308

cve-icon Vulnrichment

Updated: 2024-08-02T17:39:12.247Z

cve-icon NVD

Status : Modified

Published: 2023-07-31T15:15:10.787

Modified: 2024-11-21T08:13:17.693

Link: CVE-2023-38308

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.