CVE-2021-31761

CRITICAL

Webmin - XSS

Title source: rule

Description

Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's running process feature.

Exploits (3)

exploitdb WORKING POC
by Mesh3l_911 · pythonwebappslinux
https://www.exploit-db.com/exploits/50144
nomisec WORKING POC 5 stars
by Mesh3l911 · poc
https://github.com/Mesh3l911/CVE-2021-31761
nomisec WORKING POC 4 stars
by electronicbots · poc
https://github.com/electronicbots/CVE-2021-31761

Scores

CVSS v3 9.6
EPSS 0.8232
EPSS Percentile 99.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Details

CWE
CWE-79
Status published
Products (1)
webmin/webmin 1.973
Published Apr 25, 2021
Tracked Since Feb 18, 2026