Vulnerabilities > Webmin

DATE CVE VULNERABILITY TITLE RISK
2020-10-12 CVE-2020-8820 Cross-site Scripting vulnerability in Webmin
An XSS Vulnerability exists in Webmin 1.941 and earlier affecting the Cluster Shell Commands Endpoint.
network
low complexity
webmin CWE-79
5.4
2020-10-12 CVE-2020-12670 Cross-site Scripting vulnerability in Webmin
XSS exists in Webmin 1.941 and earlier affecting the Save function of the Read User Email Module / mailboxes Endpoint when attempting to save HTML emails.
network
low complexity
webmin CWE-79
6.1
2019-08-26 CVE-2019-15642 Code Injection vulnerability in Webmin
rpc.cgi in Webmin through 1.920 allows authenticated Remote Code Execution via a crafted object name because unserialise_variable makes an eval call.
network
low complexity
webmin CWE-94
8.8
2019-08-26 CVE-2019-15641 XXE vulnerability in Webmin
xmlrpc.cgi in Webmin through 1.930 allows authenticated XXE attacks.
network
low complexity
webmin CWE-611
6.5
2019-08-16 CVE-2019-15107 OS Command Injection vulnerability in Webmin
An issue was discovered in Webmin <=1.920.
network
low complexity
webmin CWE-78
critical
9.8
2019-06-15 CVE-2019-12840 OS Command Injection vulnerability in Webmin
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root privileges via the data parameter to update.cgi.
network
low complexity
webmin CWE-78
8.8
2019-03-21 CVE-2018-19191 Cross-site Scripting vulnerability in Webmin 1.890
Webmin 1.890 has XSS via /config.cgi?webmin, the /shell/index.cgi history parameter, /shell/index.cgi?stripped=1, or the /webminlog/search.cgi uall or mall parameter.
network
low complexity
webmin CWE-79
5.4
2019-03-07 CVE-2019-9624 Improper Privilege Management vulnerability in Webmin 1.900
Webmin 1.900 allows remote attackers to execute arbitrary code by leveraging the "Java file manager" and "Upload and Download" privileges to upload a crafted .cgi file via the /updown/upload.cgi URI.
local
low complexity
webmin CWE-269
7.8
2018-03-14 CVE-2018-8712 Path Traversal vulnerability in Webmin 1.840/1.880
An issue was discovered in Webmin 1.840 and 1.880 when the default Yes setting of "Can view any file as a log file" is enabled.
network
low complexity
webmin CWE-22
critical
9.8
2017-12-30 CVE-2017-17089 Cross-site Scripting vulnerability in Webmin
custom/run.cgi in Webmin before 1.870 allows remote authenticated administrators to conduct XSS attacks via the description field in the custom command functionality.
network
low complexity
webmin CWE-79
4.8