Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2rpj-3356-c2rw

Опубликовано: 27 мая 2026
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

Webmin before 2.640 allows mailboxes/detach.cgi XSS via an SVG document attachment that is viewed in the mailboxes component, because image/svg+xml is used instead of a safe type (e.g., text/plain).

Webmin before 2.640 allows mailboxes/detach.cgi XSS via an SVG document attachment that is viewed in the mailboxes component, because image/svg+xml is used instead of a safe type (e.g., text/plain).

EPSS

Процентиль: 5%
0.00155
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
3 месяца назад

Webmin before 2.640 allows mailboxes/detach.cgi XSS via an SVG document attachment that is viewed in the mailboxes component, because image/svg+xml is used instead of a safe type (e.g., text/plain).

CVSS3: 6.1
debian
3 месяца назад

Webmin before 2.640 allows mailboxes/detach.cgi XSS via an SVG documen ...

EPSS

Процентиль: 5%
0.00155
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79