CVE-2023-41152: XSS
Published Sep 13, 2023
·Updated
A Stored Cross-Site Scripting (XSS) vulnerability in the MIME type programs tab in Usermin 2.000 allows remote attackers to inject arbitrary web script or HTML via the handle program field while creating a new MIME type program.
Affected Software
1 affected component
Webmin Usermin=2.000
Event History
Sep 13, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-41152?
CVE-2023-41152 is a Stored Cross-Site Scripting (XSS) vulnerability in the MIME type programs tab in Usermin 2.000.
2
How does the CVE-2023-41152 vulnerability work?
The CVE-2023-41152 vulnerability allows remote attackers to inject arbitrary web script or HTML via the handle program field while creating a new MIME type program.
3
Which software versions are affected by CVE-2023-41152?
CVE-2023-41152 affects Usermin 2.000.
4
What is the severity level of CVE-2023-41152?
The severity level of CVE-2023-41152 is medium with a CVSS score of 5.4.
5
How can I fix the CVE-2023-41152 vulnerability?
To fix the CVE-2023-41152 vulnerability, update Usermin to the latest version available.