Medium severity4.8NVD Advisory· Published Dec 30, 2017· Updated May 13, 2026
CVE-2017-17089
CVE-2017-17089
Description
custom/run.cgi in Webmin before 1.870 allows remote authenticated administrators to conduct XSS attacks via the description field in the custom command functionality.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/webmin/webmin/commit/a9c97eea6c268fb83d93a817d58bac75e0d2599envdIssue TrackingPatchThird Party Advisory
- www.securityfocus.com/bid/102339nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.