Multiple Cross-Site Scripting Vulnerabilities in Usermin Software from Vendor Unknown
CVE-2016-4897
6.1MEDIUM
What is CVE-2016-4897?
Usermin software has multiple cross-site scripting vulnerabilities that can allow attackers to inject malicious scripts into web pages viewed by other users. The affected scripts are filter/save_forward.cgi, filter/save.cgi, and /man/search.cgi. These vulnerabilities can be exploited by a specially crafted URL or message, potentially leading to unauthorized actions or data exposure in the context of a user's session.