Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-38310


An issue was discovered in Webmin 2.021. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the configuration settings of the system logs functionality. The vulnerability allows an attacker to store an XSS payload in the configuration settings of specific log files. This results in the execution of that payload whenever the affected log files are accessed.


Published

2023-07-31T15:15:10.907

Last Modified

2024-11-21T08:13:17.997

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application webmin webmin 2.021 Yes

References