Vulnerabilities
9 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-45692 | Webmin before 2.202 and Virtualmin before 7.20.2 allow a network traffic loop via spoofed UDP packets on port 10000. Webmin before 2.202 and Virtualmin before 7.20.2 allow a network traffic loop via spoofed UDP packets on port 10000. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2023-47099 | A Stored Cross-Site Scripting (XSS) vulnerability in the Create Virtual Server in Virtualmin 7.7 allows remote attackers to inject arbitrary web script or HTML A Stored Cross-Site Scripting (XSS) vulnerability in the Create Virtual Server in Virtualmin 7.7 allows remote attackers to inject arbitrary web script or HTML via Description field while creating the Virtual server. NVD description · AI analysis pending | 5.4 group max | <1% | PoC |
| — | |
| CVE-2018-18208 +1 in the same advisory: …18207 | Virtualmin 6.03 allows XSS via the query string, as demonstrated by the webmin_search.cgi URI. Virtualmin 6.03 allows XSS via the query string, as demonstrated by the webmin_search.cgi URI. NVD description · AI analysis pending | 6.1 | <1% |
| — |