Unrated severityNVD Advisory· Published Jul 20, 2014· Updated May 6, 2026
CVE-2014-3886
CVE-2014-3886
Description
Cross-site scripting (XSS) vulnerability in Webmin before 1.690, when referrer checking is disabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this might overlap CVE-2014-3924.
Affected products
9cpe:2.3:a:webmin:webmin:*:*:*:*:*:*:*:*+ 8 more
- cpe:2.3:a:webmin:webmin:*:*:*:*:*:*:*:*range: <=1.680
- cpe:2.3:a:webmin:webmin:1.600:*:*:*:*:*:*:*
- cpe:2.3:a:webmin:webmin:1.610:*:*:*:*:*:*:*
- cpe:2.3:a:webmin:webmin:1.620:*:*:*:*:*:*:*
- cpe:2.3:a:webmin:webmin:1.630:*:*:*:*:*:*:*
- cpe:2.3:a:webmin:webmin:1.640:*:*:*:*:*:*:*
- cpe:2.3:a:webmin:webmin:1.650:*:*:*:*:*:*:*
- cpe:2.3:a:webmin:webmin:1.660:*:*:*:*:*:*:*
- cpe:2.3:a:webmin:webmin:1.670:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- jvn.jp/en/jp/JVN02213197/index.htmlnvdVendor Advisory
- jvndb.jvn.jp/jvndb/JVNDB-2014-000060nvdVendor Advisory
News mentions
0No linked articles in our index yet.