CVE-2023-41154: XSS
Published Sep 13, 2023
·Updated
A Stored Cross-Site Scripting (XSS) vulnerability in the scheduled cron jobs tab in Usermin 2.000 allows remote attackers to inject arbitrary web script or HTML via the value field parameter while creating a new environment variable.
Affected Software
1 affected component
Webmin Usermin=2.000
Event History
Sep 13, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-41154?
The severity of CVE-2023-41154 is medium.
2
How does CVE-2023-41154 affect Usermin?
CVE-2023-41154 affects Usermin 2.000.
3
What is the Common Weakness Enumeration (CWE) for CVE-2023-41154?
The CWE for CVE-2023-41154 is CWE-79.
4
How can remote attackers exploit CVE-2023-41154?
Remote attackers can exploit CVE-2023-41154 by injecting arbitrary web script or HTML through the value field parameter in the scheduled cron jobs tab.
5
Are there any references for CVE-2023-41154?
Yes, there are references available for CVE-2023-41154. You can find them at: [Reference 1](https://github.com/shindeanik/Usermin-2.000/blob/main/CVE-2023-41154), [Reference 2](https://webmin.com/tags/webmin-changelog/).