CVE-2023-47095: XSS
A Stored Cross-Site Scripting (XSS) vulnerability in the Custom fields of Edit Virtual Server under System Customization in Virtualmin 7.7 allows remote attackers to inject arbitrary web script or HTML via the Batch Label field while details of Virtual Server.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-47095?
CVE-2023-47095 is a Stored Cross-Site Scripting (XSS) vulnerability in the Custom fields of Edit Virtual Server under System Customization in Virtualmin 7.7.
How does CVE-2023-47095 affect Virtualmin?
CVE-2023-47095 allows remote attackers to inject arbitrary web script or HTML via the Batch Label field while details of Virtual Server.
What is the severity level of CVE-2023-47095?
CVE-2023-47095 has a severity level of medium, with a severity value of 5.4.
How can I fix CVE-2023-47095 in Virtualmin 7.7?
To fix CVE-2023-47095 in Virtualmin 7.7, it is recommended to update to the latest version or apply the necessary patches provided by Virtualmin.
What is CWE-79?
CWE-79 refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').