2023-11-01 00:55:23 +00:00
{
"id" : "CVE-2023-47099" ,
"sourceIdentifier" : "cve@mitre.org" ,
"published" : "2023-11-01T00:15:09.583" ,
2023-11-06 17:00:22 +00:00
"lastModified" : "2023-11-06T15:28:42.143" ,
"vulnStatus" : "Analyzed" ,
2023-11-01 00:55:23 +00:00
"descriptions" : [
{
"lang" : "en" ,
2023-11-01 23:00:27 +00:00
"value" : "A Stored Cross-Site Scripting (XSS) vulnerability in the Create Virtual Server in Virtualmin 7.7 allows remote attackers to inject arbitrary web script or HTML via Description field while creating the Virtual server."
2023-11-06 17:00:22 +00:00
} ,
{
"lang" : "es" ,
"value" : "Una vulnerabilidad de Cross-Site Scripting (XSS) Almacenada en Create Virtual Server en Virtualmin 7.7 permite a atacantes remotos inyectar script web o HTML arbitrario a trav\u00e9s del campo Descripci\u00f3n mientras crean el servidor Virtual."
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "REQUIRED" ,
"scope" : "CHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "LOW" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 5.4 ,
"baseSeverity" : "MEDIUM"
} ,
"exploitabilityScore" : 2.3 ,
"impactScore" : 2.7
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-79"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:virtualmin:virtualmin:7.7:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "39D7B952-7F2D-48ED-893F-DDC5039B3DC9"
}
]
}
]
2023-11-01 00:55:23 +00:00
}
] ,
"references" : [
{
"url" : "https://github.com/pavanughade43/Virtualmin-7.7/blob/main/CVE-2023-47099" ,
2023-11-06 17:00:22 +00:00
"source" : "cve@mitre.org" ,
"tags" : [
"Exploit" ,
"Third Party Advisory"
]
2023-11-01 00:55:23 +00:00
}
]
}