CVE-2011-1937 describes a cross-site scripting (XSS) vulnerability in Webmin versions 1.540 and earlier. This flaw allows local users to inject arbitrary web script or HTML by manipulating the "Full Name" field via a chfn command, specifically impacting useradmin/index.cgi and useradmin/user-lib.pl. The vulnerability has a CVSS score of 4.3, indicating a medium attack complexity and potential for partial integrity impact, but no confidentiality or availability impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.540CPE matchmatch criteria | cpe:2.3:a:webmin:webmin:*:*:*:*:*:*:*:* | ||
0.75CPE matchmatch criteria | cpe:2.3:a:webmin:webmin:0.75:*:*:*:*:*:*:* | ||
0.76CPE matchmatch criteria | cpe:2.3:a:webmin:webmin:0.76:*:*:*:*:*:*:* | ||
0.77CPE matchmatch criteria | cpe:2.3:a:webmin:webmin:0.77:*:*:*:*:*:*:* | ||
0.78CPE matchmatch criteria | cpe:2.3:a:webmin:webmin:0.78:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.