Executive brief
Webmin is a web-based interface for system administration on Unix-like systems. A security vulnerability in its email management component allows an attacker to send a specially crafted email attachment that, when viewed by a user, executes malicious scripts in their browser. This could lead to unauthorized actions being performed on behalf of the user or the theft of sensitive session information.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in Webmin's mailboxes component, specifically within 'mailboxes/detach.cgi'. The issue stems from the application serving SVG document attachments using the 'image/svg+xml' MIME type instead of a safer alternative like 'text/plain'. Because SVG files can contain embedded JavaScript, an attacker can send an email with a malicious SVG attachment; when a victim views or detaches this file through the Webmin interface, the script executes within the context of the victim's session. This is a reflected XSS attack requiring user interaction. The vulnerability is addressed in version 2.640 by improving attachment handling.
Affected products
- Webmin Webmin before 2.640
Timeline
- 2026-05-27: disclosed
- 2026-05-27: advisory