CVE-2022-36880: XSS
Published Jul 27, 2022
·Updated
The Read Mail module in Webmin 1.995 and Usermin through 1.850 allows XSS via a crafted HTML e-mail message.
Affected Software
2 affected components
Webmin Usermin<=1.850
Webmin Webmin=1.995
Event History
Jul 27, 2022
CVE Published
via MITRE·03:32 AM
Data Sourced
via MITRE·03:32 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-36880.
2
What is the severity of CVE-2022-36880?
The severity of CVE-2022-36880 is medium.
3
What software is affected by CVE-2022-36880?
The Webmin Usermin versions up to and including 1.850, as well as Webmin version 1.995, are affected by CVE-2022-36880.
4
How does CVE-2022-36880 allow XSS?
CVE-2022-36880 allows XSS through a crafted HTML e-mail message in the Read Mail module of Webmin and Usermin.
5
Is there a fix available for CVE-2022-36880?
Yes, please refer to the official website for Webmin for information on how to fix CVE-2022-36880.