Cross-site scripting vulnerability exists in session_login.cgi of Webmin versions prior to 1.970 and Usermin versions prior to 1.820. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product. As a result, a webpage may be altered or sensitive information such as a credential may be disclosed.
Metrics
Affected Vendors & Products
References
History
Wed, 08 Oct 2025 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Webmin
Webmin usermin Webmin webmin |
|
CPEs | cpe:2.3:a:webmin:usermin:*:*:*:*:*:*:*:* cpe:2.3:a:webmin:webmin:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Webmin
Webmin usermin Webmin webmin |
Wed, 06 Nov 2024 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:webmin:webmin:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Webmin
Webmin usermin Webmin webmin |
Tue, 05 Nov 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-79 |

Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2024-11-06T21:34:36.873Z
Reserved: 2024-05-28T05:38:38.739Z
Link: CVE-2024-36453

Updated: 2024-08-02T03:37:05.102Z

Status : Analyzed
Published: 2024-07-10T07:15:03.177
Modified: 2025-10-08T16:54:02.857
Link: CVE-2024-36453

No data.