CVE-2023-41156: XSS
Published Sep 14, 2023
·Updated
A Stored Cross-Site Scripting (XSS) vulnerability in the filter and forward mail tab in Usermin 2.001 allows remote attackers to inject arbitrary web script or HTML via the save to new folder named field while creating a new filter.
Affected Software
1 affected component
Webmin Usermin=2.001
Event History
Sep 14, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability type of CVE-2023-41156?
Stored Cross-Site Scripting (XSS).
2
How does CVE-2023-41156 affect Usermin?
It allows remote attackers to inject arbitrary web script or HTML via the 'save to new folder named' field while creating a new filter.
3
What is the severity of CVE-2023-41156?
The severity of CVE-2023-41156 is medium with a CVSS score of 5.4.
4
What is the Common Weakness Enumeration (CWE) ID associated with CVE-2023-41156?
The CWE ID associated with CVE-2023-41156 is CWE-79.
5
How can I fix CVE-2023-41156?
To fix CVE-2023-41156, update to a version of Usermin that is not affected by the vulnerability.