Vulnerability Description
Webmin before 1.860 has XSS with resultant remote code execution. Under the 'Others/File Manager' menu, there is a 'Download from remote URL' option to download a file from a remote server. After setting up a malicious server, one can wait for a file download request and then send an XSS payload that will lead to Remote Code Execution, as demonstrated by an OS command in the value attribute of a name='cmd' input element.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Webmin | Webmin | <= 1.850 |
Related Weaknesses (CWE)
References
- http://www.webmin.com/changes.htmlRelease NotesVendor Advisory
- http://www.webmin.com/security.htmlVendor Advisory
- https://blogs.securiteam.com/index.php/archives/3430ExploitThird Party Advisory
- https://github.com/webmin/webmin/commit/0c58892732ee7610a7abba5507614366d382c9c9PatchThird Party Advisory
- http://www.webmin.com/changes.htmlRelease NotesVendor Advisory
- http://www.webmin.com/security.htmlVendor Advisory
- https://blogs.securiteam.com/index.php/archives/3430ExploitThird Party Advisory
- https://github.com/webmin/webmin/commit/0c58892732ee7610a7abba5507614366d382c9c9PatchThird Party Advisory
FAQ
What is CVE-2017-15646?
CVE-2017-15646 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Webmin before 1.860 has XSS with resultant remote code execution. Under the 'Others/File Manager' menu, there is a 'Download from remote URL' option to download a file from a remote server. After sett...
How severe is CVE-2017-15646?
CVE-2017-15646 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-15646?
Check the references section above for vendor advisories and patch information. Affected products include: Webmin Webmin.