Stored Cross-Site Scripting Vulnerability in Usermin by Virtualmin
CVE-2023-41160
5.4MEDIUM
What is CVE-2023-41160?
Usermin 2.001 contains a Stored Cross-Site Scripting (XSS) vulnerability found in the SSH configuration section. This flaw allows remote attackers to inject and execute arbitrary web scripts or HTML through the key name field when adding an authorized key. Such an exploitation could lead to the manipulation of the web interface, potentially compromising user data and session information, thereby creating significant security risks.