Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xjf8-qhj9-9w5r

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

XSS exists in Webmin 1.941 and earlier affecting the Save function of the Read User Email Module / mailboxes Endpoint when attempting to save HTML emails. This module parses any output without sanitizing SCRIPT elements, as opposed to the View function, which sanitizes the input correctly. A malicious user can send any JavaScript payload into the message body and execute it if the user decides to save that email.

XSS exists in Webmin 1.941 and earlier affecting the Save function of the Read User Email Module / mailboxes Endpoint when attempting to save HTML emails. This module parses any output without sanitizing SCRIPT elements, as opposed to the View function, which sanitizes the input correctly. A malicious user can send any JavaScript payload into the message body and execute it if the user decides to save that email.

EPSS

Процентиль: 58%
0.00359
Низкий

Связанные уязвимости

CVSS3: 6.1
nvd
больше 5 лет назад

XSS exists in Webmin 1.941 and earlier affecting the Save function of the Read User Email Module / mailboxes Endpoint when attempting to save HTML emails. This module parses any output without sanitizing SCRIPT elements, as opposed to the View function, which sanitizes the input correctly. A malicious user can send any JavaScript payload into the message body and execute it if the user decides to save that email.

CVSS3: 6.1
debian
больше 5 лет назад

XSS exists in Webmin 1.941 and earlier affecting the Save function of ...

EPSS

Процентиль: 58%
0.00359
Низкий