CVE-2023-41157: XSS
Multiple stored cross-site scripting (XSS) vulnerabilities in Usermin 2.000 allow remote attackers to inject arbitrary web script or HTML via the folder name parameter while creating the folder to manage the folder tab, filter tab, and forward mail tab.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Usermin vulnerability?
The vulnerability ID for this Usermin vulnerability is CVE-2023-41157.
What is the severity level of CVE-2023-41157?
The severity level of CVE-2023-41157 is medium, with a score of 5.4.
How can remote attackers exploit CVE-2023-41157?
Remote attackers can exploit CVE-2023-41157 by injecting arbitrary web script or HTML via the folder name parameter while creating the folder to manage the folder tab, filter tab, and forward mail tab.
Which version of Usermin is affected by CVE-2023-41157?
Usermin version 2.000 is affected by CVE-2023-41157.
Is there a fix available for CVE-2023-41157?
Yes, a fix for CVE-2023-41157 is available. It is recommended to update Usermin to a version that includes the fix.