Webmin Stored XSS Vulnerability Lets Attackers Exploit Root Users
ID: 58733a49-58c6-50b1-aeff-f2ad8027d3b9
STIX ID: report--58733a49-58c6-50b1-aeff-f2ad8027d3b9
Feed Name: GBHackers
A stored XSS vulnerability (CVE-2026-22678) in Webmin versions prior to 2.641 allows an authenticated, untrusted user who can create or edit notification email templates to inject JavaScript that executes when privileged users (including root) view the template; this can enable session hijacking, credential theft, and unauthorized administrative actions. The issue resides in the System and Server Status module due to improper input sanitization, was responsibly disclosed by a researcher, and has been fixed in Webmin 2.641—administrators are advised to upgrade immediately, audit templates, and review permissions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
