CVE-2024-36450
🔶 mediumSummary
Cross-site scripting vulnerability exists in sysinfo.cgi of Webmin versions prior to 1.910. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product. As a result, a session ID may be obtained, a webpage may be altered, or a server may be halted.
CVSS Score
5.4
Medium
EPSS Score
0.2
Exploit Probability
Published Date
2024-07-10
First Seen: 2026-01-05
📊 Relative Risk Intelligence
This CVE is Lower Risk - more severe than 22.8% of all 330,193 vulnerabilities in our database.
#255,023
Below average severity
Severity Percentile
🎯 CISA SSVC Assessment Updated: Jul 10, 2024
🔍 Exploitation Status
None
No known exploits
⚙️ Automatable
NO
Requires human interaction
💥 Technical Impact
Partial
Limited system impact
SSVC data provided by
CISA
Last Modified
2025-03-13
Source
NVD 🔗
CVSS Vector 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CWE IDs (Weakness Types)