CVE-2017-17089: Webmin

Medium severity, CVSS 4.8. EPSS: 0.8% chance of exploitation in the next 30 days.

custom/run.cgi in Webmin before 1.870 allows remote authenticated administrators to conduct XSS attacks via the description field in the custom command functionality.

Affected products

  • Webmin Webmin: up to and including 1.860

Published 2017-12-30. Last modified 2026-06-17.