Описание
Webmin before 2.640 allows mailboxes/detach.cgi XSS via an SVG document attachment that is viewed in the mailboxes component, because image/svg+xml is used instead of a safe type (e.g., text/plain).
EPSS
Процентиль: 12%
0.00216
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 6.1
debian
3 месяца назад
Webmin before 2.640 allows mailboxes/detach.cgi XSS via an SVG documen ...
CVSS3: 6.1
github
3 месяца назад
Webmin before 2.640 allows mailboxes/detach.cgi XSS via an SVG document attachment that is viewed in the mailboxes component, because image/svg+xml is used instead of a safe type (e.g., text/plain).
EPSS
Процентиль: 12%
0.00216
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-79