V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2021-31761
DEB
CriticalConfirmedExploit available

Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's running process featu…

CVSS
9.6
Critical
EPSS
0.34
p98
Published
2021-01-01
Updated
2021-01-01
Description

Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's running process feature.

Tags · CWE
Pre-authXSS
CWE-79
CAPEC-63
CAPEC-85
CAPEC-209
CAPEC-588
CAPEC-591
CAPEC-592
Affected products
Webmin
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Timeline
2021-01-01
Published
2021-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: R
Required (R)
Scope
S: C
Changed (C)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.336 · p98
Known exploited (KEV)
No
Known exploits — Сканер-ВС
50144
exploitdb · https://www.exploit-db.com/exploits/50144
Enterprise
CVE-2021-31761
github-poc · https://github.com/electronicbots/CVE-2021-31761
Enterprise
Affected products
ProductVendorStatus
webminTracked
webmin*Tracked
Source databases
DEB
CVE