Skip to content

bl4ckmenace/Webmin-XSS-HTTP-Module

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

5 Commits
 
 

Repository files navigation

Webmin XSS HTTP-Module

Webmin versions 1.995 and below have a vulnerability that lets an attacker bypass referrers and run XSS code.
With this, an attacker can steal cookies or perform actions as another user.
The issue is easier to exploit if the account has HTTP-Tunnel module permissions.

Affected URL:
https://example.com/tunnel/link.cgi/

POC video:
https://youtu.be/i5MieKoY64Q

If you are using an older Webmin version, update as soon as possible.
Security tools like VPNs or anything that hides referrers are not enough to stop this attack.

References

If you need to report a security issue, contact the Webmin team directly.

About

XSS in Webmin 1.995 & Below (HTTP Module)

Resources

Stars

Watchers

Forks

Contributors