First published: Wed Sep 13 2023(Updated: )
A Stored Cross-Site Scripting (XSS) vulnerability in the scheduled cron jobs tab in Usermin 2.000 allows remote attackers to inject arbitrary web script or HTML via the value field parameter while creating a new environment variable.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webmin Usermin | =2.000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-41154 is medium.
CVE-2023-41154 affects Usermin 2.000.
The CWE for CVE-2023-41154 is CWE-79.
Remote attackers can exploit CVE-2023-41154 by injecting arbitrary web script or HTML through the value field parameter in the scheduled cron jobs tab.
Yes, there are references available for CVE-2023-41154. You can find them at: [Reference 1](https://github.com/shindeanik/Usermin-2.000/blob/main/CVE-2023-41154), [Reference 2](https://webmin.com/tags/webmin-changelog/).