Stored Cross-Site Scripting Vulnerability in Webmin and Usermin Products
CVE-2023-41155
5.4MEDIUM
What is CVE-2023-41155?
A vulnerability allows remote attackers to exploit a Stored Cross-Site Scripting (XSS) flaw in the mail forwarding and replies tab of Webmin and Usermin 2.000. By manipulating the 'forward to' field when setting up a mail forwarding rule, an attacker can inject arbitrary web scripts or HTML code. This exploitation could lead to unauthorized access and potentially affect other users accessing the compromised system.