CVE-2023-41158: XSS
Published Sep 13, 2023
·Updated
A Stored Cross-Site Scripting (XSS) vulnerability in the MIME type programs tab in Usermin 2.000 allows remote attackers to inject arbitrary web script or HTML via the description field while creating a new MIME type program.
Affected Software
1 affected component
Webmin Usermin=2.000
Event History
Sep 13, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2023-41158.
2
What is the severity of CVE-2023-41158?
The severity of CVE-2023-41158 is medium with a CVSS score of 5.4.
3
What is the affected software?
The affected software is Usermin version 2.000.
4
How does the vulnerability CVE-2023-41158 work?
The vulnerability allows remote attackers to inject arbitrary web script or HTML via the description field while creating a new MIME type program in the MIME type programs tab in Usermin 2.000.
5
Is there a fix available for CVE-2023-41158?
As of now, there is no information available about an official fix for CVE-2023-41158. It is recommended to follow the references provided for any updates or patches.