First published: Wed Jul 27 2022(Updated: )
The Read Mail module in Webmin 1.995 and Usermin through 1.850 allows XSS via a crafted HTML e-mail message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Usermin | <=1.850 | |
Webmin | =1.995 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2022-36880.
The severity of CVE-2022-36880 is medium.
The Webmin Usermin versions up to and including 1.850, as well as Webmin version 1.995, are affected by CVE-2022-36880.
CVE-2022-36880 allows XSS through a crafted HTML e-mail message in the Read Mail module of Webmin and Usermin.
Yes, please refer to the official website for Webmin for information on how to fix CVE-2022-36880.