CVE-2024-36451
Improper handling of insufficient permissions or privileges vulnerability exists in ajaxterm module of Webmin prior to 2.003.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.57%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Improper handling of insufficient permissions or privileges vulnerability exists in ajaxterm module of Webmin prior to 2.003. If this vulnerability is exploited, a console session may be hijacked by an unauthorized user. As a result, data within a system may be referred, a webpage may be altered, or a server may be permanently halted.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.57% probability · 45th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-280
- Affected
- webmin/webmin
- Source
- vultures@jpcert.or.jp
References
- https://jvn.jp/en/jp/JVN81442045/Third Party Advisory
- https://webmin.com/Product
- https://jvn.jp/en/jp/JVN81442045/Third Party Advisory
- https://webmin.com/Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.