A Stored Cross-Site Scripting (XSS) vulnerability in the filter and forward mail tab in Usermin 2.001 allows remote attackers to inject arbitrary web script or HTML via the save to new folder named field while creating a new filter.
References
Link | Resource |
---|---|
https://github.com/shindeanik/Usermin-2.001/blob/main/CVE-2023-41156 | Third Party Advisory |
https://webmin.com/tags/webmin-changelog/ | Release Notes |
Configurations
History
No history.
Information
Published : 2023-09-14 21:15
Updated : 2023-09-19 16:28
NVD link : CVE-2023-41156
Mitre link : CVE-2023-41156
CVE.ORG link : CVE-2023-41156
JSON object : View
Products Affected
webmin
- usermin
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')