Cross-Site Scripting in Webmin and Usermin Email Modules
CVE-2022-36880

6.1MEDIUM

Key Information:

Vendor

Webmin

Vendor
CVE Published:
27 July 2022

What is CVE-2022-36880?

The Read Mail module in Webmin 1.995 and Usermin up to version 1.850 is susceptible to Cross-Site Scripting (XSS) attacks through specially crafted HTML email messages. An attacker could exploit this vulnerability to execute arbitrary scripts in the context of the user's session, potentially compromising sensitive information and leading to unauthorized actions. It is crucial for users of these products to apply necessary patches and mitigate the risk of being targeted by such vulnerabilities.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2022-36880 : Cross-Site Scripting in Webmin and Usermin Email Modules