Cross-Site Scripting in Webmin and Usermin Email Modules
CVE-2022-36880
6.1MEDIUM
What is CVE-2022-36880?
The Read Mail module in Webmin 1.995 and Usermin up to version 1.850 is susceptible to Cross-Site Scripting (XSS) attacks through specially crafted HTML email messages. An attacker could exploit this vulnerability to execute arbitrary scripts in the context of the user's session, potentially compromising sensitive information and leading to unauthorized actions. It is crucial for users of these products to apply necessary patches and mitigate the risk of being targeted by such vulnerabilities.