Stored Cross-Site Scripting Vulnerability in Usermin Mail Filtering Feature
CVE-2023-41156
5.4MEDIUM
What is CVE-2023-41156?
A vulnerability exists in Usermin 2.001 that allows remote attackers to perform a Stored Cross-Site Scripting (XSS) attack. This flaw is found in the mail filter and forward tab, specifically when creating a new filter. By manipulating the 'save to new folder named' field, an attacker can inject arbitrary web scripts or HTML code. If successfully executed, this could lead to unauthorized actions on behalf of the user, potentially compromising sensitive information and overall system integrity.