Home

Description

Cross-site request forgery vulnerability exists in ajaxterm module of Webmin versions prior to 2.003. If this vulnerability is exploited, unintended operations may be performed when a user views a malicious page while logged in. As a result, data within a system may be referred, a webpage may be altered, or a server may be permanently halted.

PUBLISHED Reserved 2024-05-28 | Published 2024-07-10 | Updated 2024-11-05 | Assigner jpcert

Problem types

Cross-site request forgery (CSRF)

Product status

versions prior to 2.003
affected

References

webmin.com/

jvn.jp/en/jp/JVN81442045/

webmin.com/

jvn.jp/en/jp/JVN81442045/

cve.org (CVE-2024-36452)

nvd.nist.gov (CVE-2024-36452)

Download JSON