Executive brief
Webmin, a popular web-based interface for system administration, contains a security flaw in its System and Server Status module. An attacker with low-level access to the system can inject malicious scripts into email template descriptions. If an administrator views these templates, the attacker could potentially take control of the administrator's session or execute unauthorized commands, compromising the server's security.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Webmin versions prior to 2.641. The flaw is located in the email template description field within the System and Server Status module. Specifically, input provided to 'save_tmpl.cgi' is not properly sanitized before being stored, and it is subsequently rendered without escaping in 'list_tmpls.cgi'. A low-privileged authenticated attacker can exploit this by injecting malicious JavaScript. When a victim (typically an administrator) views the list of templates, the script executes in their browser context, potentially allowing for session hijacking or arbitrary command execution. The issue is resolved in Webmin version 2.641.
Affected products
- Webmin Webmin before 2.641
Timeline
- 2026-05-10: patched: Webmin 2.641 released
- 2026-05-21: disclosed: CVE-2026-22678 published