{"id":"CVE-2017-9313","details":"Multiple Cross-site scripting (XSS) vulnerabilities in Webmin before 1.850 allow remote attackers to inject arbitrary web script or HTML via the sec parameter to view_man.cgi, the referers parameter to change_referers.cgi, or the name parameter to save_user.cgi. NOTE: these issues were not fixed in 1.840.","modified":"2026-07-08T16:54:25.484443Z","published":"2017-07-04T02:29:00.283Z","references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/99373"},{"type":"ADVISORY","url":"http://www.securitytracker.com/id/1038814"},{"type":"ADVISORY","url":"http://www.webmin.com/changes.html"},{"type":"FIX","url":"https://github.com/webmin/webmin/commit/a330e913ee099cb9c586ce1b9267647fc566c1ab"},{"type":"FIX","url":"https://github.com/webmin/webmin/commit/c2d4a90639afb2403979aa91ba75cb332ae16d1b"},{"type":"EVIDENCE","url":"http://seclists.org/bugtraq/2017/Jul/3"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/webmin/webmin","events":[{"introduced":"0"},{"last_affected":"867fda60dc99af153822fcdd9caa5c18d63bcc6a"},{"fixed":"a330e913ee099cb9c586ce1b9267647fc566c1ab"},{"fixed":"c2d4a90639afb2403979aa91ba75cb332ae16d1b"}],"database_specific":{"cpe":"cpe:2.3:a:webmin:webmin:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"1.840"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["1.840","1.831","1.830","1.820","1.810","1.801","1.800","1.790","1.780","1.770","1.760","1.750","1.740","1.730","1.720","1.710","1.700"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-9313.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}