Multiple Stored Cross-Site Scripting Vulnerabilities in Usermin by Webmin
CVE-2023-41161
5.4MEDIUM
What is CVE-2023-41161?
Usermin 2.000 has multiple stored cross-site scripting vulnerabilities that enable remote attackers to inject arbitrary web scripts or HTML. This can occur via the key comment field across various pages, including public key details and key server pages. Exploiting these XSS vulnerabilities could allow attackers to manipulate the user interface and execute unauthorized actions on behalf of users.