{ "id": "CVE-2023-41156", "sourceIdentifier": "cve@mitre.org", "published": "2023-09-14T21:15:10.630", "lastModified": "2024-11-21T08:20:41.177", "vulnStatus": "Modified", "cveTags": [], "descriptions": [ { "lang": "en", "value": "A Stored Cross-Site Scripting (XSS) vulnerability in the filter and forward mail tab in Usermin 2.001 allows remote attackers to inject arbitrary web script or HTML via the save to new folder named field while creating a new filter." }, { "lang": "es", "value": "Una vulnerabilidad de Cross-Site Scripting (XSS) almacenado en la pesta\u00f1a de filtro y reenv\u00edo de correo en Usermin 2.001 permite a atacantes remotos inyectar script web o HTML de su elecci\u00f3n a trav\u00e9s del campo llamado \"guardar en nueva carpeta\" mientras crean un nuevo filtro." } ], "metrics": { "cvssMetricV31": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N", "baseScore": 5.4, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "REQUIRED", "scope": "CHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE" }, "exploitabilityScore": 2.3, "impactScore": 2.7 } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-79" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:webmin:usermin:2.001:*:*:*:*:*:*:*", "matchCriteriaId": "9CE9B3CB-9D26-492D-9584-317C5BE061EE" } ] } ] } ], "references": [ { "url": "https://github.com/shindeanik/Usermin-2.001/blob/main/CVE-2023-41156", "source": "cve@mitre.org", "tags": [ "Third Party Advisory" ] }, { "url": "https://webmin.com/tags/webmin-changelog/", "source": "cve@mitre.org", "tags": [ "Release Notes" ] }, { "url": "https://github.com/shindeanik/Usermin-2.001/blob/main/CVE-2023-41156", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory" ] }, { "url": "https://webmin.com/tags/webmin-changelog/", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Release Notes" ] } ] }