An issue was discovered in Webmin 2.021. A Cross-site Scripting (XSS) Bypass vulnerability was discovered in the file upload functionality. Normally, the application restricts the upload of certain file types such as .svg, .php, etc., and displays an error message if a prohibited file type is detected. However, by following certain steps, an attacker can bypass these restrictions and inject malicious code.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2023-07-31T00:00:00

Updated: 2023-07-31T00:00:00

Reserved: 2023-07-14T00:00:00


Link: CVE-2023-38306

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-07-31T15:15:10.663

Modified: 2023-08-04T12:57:14.733


Link: CVE-2023-38306

JSON object: View

cve-icon Redhat Information

No data.

CWE