CVE-2024-36453
Last modified
CVE-2024-36453 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. Cross-site scripting vulnerability exists in session_login.cgi of Webmin versions prior to 1.970 and Usermin versions prior to 1.820. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product. EPSS estimates a 0.40% chance of exploitation in the next 30 days.
Description
Cross-site scripting vulnerability exists in session_login.cgi of Webmin versions prior to 1.970 and Usermin versions prior to 1.820. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product. As a result, a webpage may be altered or sensitive information such as a credential may be disclosed.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Webmin | Usermin | < 1.820 |
| Webmin | Webmin | < 1.970 |
References
- https://jvn.jp/en/jp/JVN81442045/Third Party Advisory
- https://webmin.com/Product
- https://webmin.com/usermin/Product
- https://jvn.jp/en/jp/JVN81442045/Third Party Advisory
- https://webmin.com/Product
- https://webmin.com/usermin/Product
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-36453?
How severe is CVE-2024-36453?
How do I fix CVE-2024-36453?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-36446The provisioning manager component of Mitel MiVoice MX-ONE t…8.8
- CVE-2024-36448** UNSUPPORTED WHEN ASSIGNED ** Server-Side Request Forgery …7.3
- CVE-2024-3645The Essential Addons for Elementor Pro plugin for WordPress …6.4
- CVE-2024-36450Cross-site scripting vulnerability exists in sysinfo.cgi of …5.4
- CVE-2024-36451Improper handling of insufficient permissions or privileges …8.8
- CVE-2024-36452Cross-site request forgery vulnerability exists in ajaxterm …3.1
- CVE-2024-36454Use of uninitialized resource issue exists in IPCOM EX2 Seri…5.3
- CVE-2024-36455An improper input validation allows an unauthenticated attac…9.4
- CVE-2024-36456This vulnerability allows an unauthenticated attacker to ach…9.4
- CVE-2024-36457The vulnerability allows an attacker to bypass the authentic…5.3
- CVE-2024-36458The vulnerability allows a malicious low-privileged PAM user…5.1
- CVE-2024-36459A CRLF cross-site scripting vulnerability has been identifie…8.4
Are you affected by CVE-2024-36453?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
