Logo
vulnerabilityCVE-2020-8821
Name
CVE-2020-8821
Source
NVD ( link)Debian ( link)
Description
An Improper Data Validation Vulnerability exists in Webmin 1.941 and earlier affecting the Command Shell Endpoint. A user may enter HTML code into the Command field and submit it. Then, after visiting the Action Logs Menu and displaying logs, the HTML code will be rendered (however, JavaScript is not executed). Changes are kept across users.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
webmin
Exploitable

Vulnerability Ratings#


5.4
CVSSv31
3.5
CVSSv2

Others affected components#


Name
Project
Project Version
Version
Status
yocto
kirkstone
1.850
Exploitable
yocto
master
2.641
Not Affected